
Live Composer – Free WordPress Website Builder Security & Risk Analysis
wordpress.org/plugins/live-composer-page-builderPage builder for WordPress with drag and drop header/footer editing, responsive settings, and animations. Compatible with Gutenberg block editor.
Is Live Composer – Free WordPress Website Builder Safe to Use in 2026?
Use With Caution
Score 60/100Live Composer – Free WordPress Website Builder has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The live-composer-page-builder plugin v2.1.8 exhibits several concerning security weaknesses, despite some positive security practices. The presence of 21 AJAX handlers, with two lacking authorization checks, presents a direct attack vector. Furthermore, the taint analysis revealed two high-severity flows with unsanitized paths, indicating potential for code injection or other serious exploits. The plugin's history of 11 known CVEs, including one currently unpatched and three high-severity vulnerabilities, strongly suggests a pattern of recurring security flaws, particularly in areas like missing authorization, CSRF, XSS, and deserialization of untrusted data. While the plugin utilizes prepared statements for the majority of its SQL queries and has a significant number of capability checks, these strengths are overshadowed by the identified vulnerabilities and the apparent ongoing struggle to maintain a secure codebase. The significant number of known CVEs and the single unpatched critical vulnerability are major red flags.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- Unpatched CVE
- History of high severity CVEs
- Recurring deserialization vulnerabilities
- Recurring XSS vulnerabilities
- Recurring CSRF vulnerabilities
- Recurring Missing Authorization vulnerabilities
- Low percentage of properly escaped output
Live Composer – Free WordPress Website Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
11 total CVEs
Page Builder: Live Composer <= 2.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
Live Composer – Free WordPress Website Builder <= 2.0.2 - Authenticated (Contributor+) PHP Object Injection via dslc_module_posts_output Shortcode
Live Composer – Free WordPress Website Builder <= 2.0.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
Page Builder: Live Composer <= 1.5.42 - Authenticated (Contributor+) Stored Cross-Site Scripting
Page Builder: Live Composer <= 1.5.42 - Authenticated (Contributor+) PHP Object Injection
Page Builder: Live Composer <= 1.5.47 - Authenticated (Author+) Stored Cross-Site Scripting
Page Builder: Live Composer <= 1.5.38 - Missing Authorization
Page Builder: Live Composer <= 1.5.35 - Cross-Site Request Forgery
Page Builder: Live Composer <= 1.5.23 - Authenticated (Contributor+) Stored Cross-Site Scripting
Page Builder: Live Composer <= 1.5.25 - Authenticated (Author+) PHP Object Injection
Page Builder: Live Composer <= 1.5.22 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Live Composer – Free WordPress Website Builder Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Live Composer – Free WordPress Website Builder Attack Surface
AJAX Handlers 21
Shortcodes 43
WordPress Hooks 115
Maintenance & Trust
Live Composer – Free WordPress Website Builder Maintenance & Trust
Maintenance Signals
Community Trust
Live Composer – Free WordPress Website Builder Alternatives
Visual Composer Website Builder
visualcomposer
Drag and drop page builder that gives the freedom to design WordPress websites, landing pages, custom themes, maintenance mode & coming soon pages.
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode
coming-soon
Easy Drag & Drop Page Builder. A complete solution to create a WordPress Website, Custom Themes, Landing Pages, Coming Soon & Maintenance Mode Pages.
Page Builder by SiteOrigin
siteorigin-panels
Build responsive page layouts using the widgets you know and love using this simple drag and drop page builder.
Kubio AI Page Builder
kubio
Using the power of AI, Kubio gives you a head start by generating a first draft of your website, which you can further customize to your liking.
Brizy – Page Builder
brizy
A page builder that is fast & easy, Brizy is a next-gen website builder that anyone can use. No designer or developer skills required.
Live Composer – Free WordPress Website Builder Developer Profile
2 plugins · 10K total installs
How We Detect Live Composer – Free WordPress Website Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/live-composer-page-builder/assets/css/admin.css/wp-content/plugins/live-composer-page-builder/assets/css/frontend.css/wp-content/plugins/live-composer-page-builder/assets/css/frontend-responsive.css/wp-content/plugins/live-composer-page-builder/assets/css/frontend-editor.css/wp-content/plugins/live-composer-page-builder/assets/js/frontend.js/wp-content/plugins/live-composer-page-builder/assets/js/frontend-editor.js/wp-content/plugins/live-composer-page-builder/assets/js/admin.js/wp-content/plugins/live-composer-page-builder/assets/js/plugins/wp-media-uploader.js+37 more/wp-content/plugins/live-composer-page-builder/assets/js/frontend.js/wp-content/plugins/live-composer-page-builder/assets/js/frontend-editor.js/wp-content/plugins/live-composer-page-builder/assets/js/admin.js/wp-content/plugins/live-composer-page-builder/assets/css/admin.css?ver=/wp-content/plugins/live-composer-page-builder/assets/css/frontend.css?ver=/wp-content/plugins/live-composer-page-builder/assets/css/frontend-responsive.css?ver=/wp-content/plugins/live-composer-page-builder/assets/css/frontend-editor.css?ver=/wp-content/plugins/live-composer-page-builder/assets/js/frontend.js?ver=/wp-content/plugins/live-composer-page-builder/assets/js/frontend-editor.js?ver=/wp-content/plugins/live-composer-page-builder/assets/js/admin.js?ver=HTML / DOM Fingerprints
dslc-moduledslc-sectiondslc-rowdslc-column<!-- Live Composer Content --><!-- Live Composer Editor --><!-- Live Composer Settings --><!-- Live Composer Templates -->+1 moredata-dslc-moduledata-dslc-iddata-dslc-rowdata-dslc-columndata-dslc-sectiondslc_live_composer_datadslc_live_composer_settingsdslc_live_composer_modulesdslc_live_composer_templatesdslc_live_composer_optionsdslc_live_composer_editor+2 more