Live Demo Sandbox – Demo Site per Visitor Security & Risk Analysis

wordpress.org/plugins/live-demo-sandbox

A powerful WordPress plugin that creates a sandbox for each visitor, ideal for showcasing custom-made themes and plugins.

0 active installs v1.0.1 PHP 7.4+ WP 5.3+ Updated Oct 26, 2024
instancelive-demosandbox
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Live Demo Sandbox – Demo Site per Visitor Safe to Use in 2026?

Generally Safe

Score 92/100

Live Demo Sandbox – Demo Site per Visitor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "live-demo-sandbox" v1.0.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices in output escaping, with 100% of outputs being properly escaped, and a high percentage (78%) of its SQL queries utilize prepared statements. The absence of known CVEs and a clean vulnerability history suggests a generally stable and well-maintained codebase concerning external vulnerabilities. However, the plugin's attack surface is a notable concern. It exposes four AJAX handlers, two of which lack any authentication checks. This creates a significant risk of unauthorized actions if these handlers are exploitable. While taint analysis did not reveal critical or high severity issues, the presence of two flows with unsanitized paths, even if not leading to critical vulnerabilities in this version, warrants caution and suggests potential areas for future improvement.

Overall, the plugin's strength lies in its internal code hygiene regarding output and SQL, but its external-facing attack surface, particularly the unprotected AJAX endpoints, is a clear vulnerability. The lack of historical vulnerabilities is a positive indicator, but it does not negate the immediate risks presented by the current static analysis findings. A balanced approach would be to address the unprotected AJAX handlers as a priority while continuing to monitor for any emerging vulnerabilities in future updates.

Key Concerns

  • AJAX handlers without auth checks
  • Flows with unsanitized paths
Vulnerabilities
None known

Live Demo Sandbox – Demo Site per Visitor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Live Demo Sandbox – Demo Site per Visitor Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Live Demo Sandbox – Demo Site per Visitor Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
18 prepared
Unescaped Output
0
28 escaped
Nonce Checks
1
Capability Checks
2
File Operations
13
External Requests
3
Bundled Libraries
0

SQL Query Safety

78% prepared23 total queries

Output Escaping

100% escaped28 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
homePage (classes\Setup\AdminPage.php:79)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Live Demo Sandbox – Demo Site per Visitor Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 4

authwp_ajax_slds_complete_setupsnippets\ext-installer.php:24
noprivwp_ajax_slds_login_to_adminsnippets\ext-installer.php:25
noprivwp_ajax_slds_init_internal_sessionsnippets\ext-installer.php:28
noprivwp_ajax_slds_internal_requestsnippets\ext-installer.php:29
WordPress Hooks 14
actionadmin_menuclasses\Setup\AdminPage.php:28
actionadmin_enqueue_scriptsclasses\Setup\AdminPage.php:29
filtercron_schedulesclasses\Setup\Cron.php:25
actioninitclasses\Setup\Cron.php:26
actioninitclasses\Setup\SandboxSetup.php:22
actionadmin_enqueue_scriptsclasses\Setup\Scripts.php:29
actionadmin_enqueue_scriptsclasses\Setup\Scripts.php:32
actioninitclasses\Setup\Scripts.php:35
actionadmin_enqueue_scriptsclasses\Setup\Scripts.php:38
actioninitsnippets\ext-installer.php:17
actioninitsnippets\ext-installer.php:18
actionwp_enqueue_scriptssnippets\ext-installer.php:19
actionadmin_enqueue_scriptssnippets\ext-installer.php:20
actiontemplate_redirectsnippets\ext-installer.php:21
Maintenance & Trust

Live Demo Sandbox – Demo Site per Visitor Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 26, 2024
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Live Demo Sandbox – Demo Site per Visitor Developer Profile

JK

3 plugins · 10 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Live Demo Sandbox – Demo Site per Visitor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/live-demo-sandbox/dist/admin-dashboard.js/wp-content/plugins/live-demo-sandbox/dist/libraries/translation-loader.js
Script Paths
/wp-content/plugins/live-demo-sandbox/dist/admin-dashboard.js/wp-content/plugins/live-demo-sandbox/dist/libraries/translation-loader.js
Version Parameters
live-demo-sandbox/admin-dashboard.js?ver=live-demo-sandbox/libraries/translation-loader.js?ver=

HTML / DOM Fingerprints

Data Attributes
id="Solidie_Sandbox_Backend_Dashboard"data-configsdata-hostsdata-meta_data
JS Globals
window.slds_demo_user_auto_created
Shortcode Output
<div id="Solidie_Sandbox_Backend_Dashboard"data-configsdata-hostsdata-meta_data
FAQ

Frequently Asked Questions about Live Demo Sandbox – Demo Site per Visitor