
Live Demo Sandbox – Demo Site per Visitor Security & Risk Analysis
wordpress.org/plugins/live-demo-sandboxA powerful WordPress plugin that creates a sandbox for each visitor, ideal for showcasing custom-made themes and plugins.
Is Live Demo Sandbox – Demo Site per Visitor Safe to Use in 2026?
Generally Safe
Score 92/100Live Demo Sandbox – Demo Site per Visitor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "live-demo-sandbox" v1.0.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices in output escaping, with 100% of outputs being properly escaped, and a high percentage (78%) of its SQL queries utilize prepared statements. The absence of known CVEs and a clean vulnerability history suggests a generally stable and well-maintained codebase concerning external vulnerabilities. However, the plugin's attack surface is a notable concern. It exposes four AJAX handlers, two of which lack any authentication checks. This creates a significant risk of unauthorized actions if these handlers are exploitable. While taint analysis did not reveal critical or high severity issues, the presence of two flows with unsanitized paths, even if not leading to critical vulnerabilities in this version, warrants caution and suggests potential areas for future improvement.
Overall, the plugin's strength lies in its internal code hygiene regarding output and SQL, but its external-facing attack surface, particularly the unprotected AJAX endpoints, is a clear vulnerability. The lack of historical vulnerabilities is a positive indicator, but it does not negate the immediate risks presented by the current static analysis findings. A balanced approach would be to address the unprotected AJAX handlers as a priority while continuing to monitor for any emerging vulnerabilities in future updates.
Key Concerns
- AJAX handlers without auth checks
- Flows with unsanitized paths
Live Demo Sandbox – Demo Site per Visitor Security Vulnerabilities
Live Demo Sandbox – Demo Site per Visitor Release Timeline
Live Demo Sandbox – Demo Site per Visitor Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Live Demo Sandbox – Demo Site per Visitor Attack Surface
AJAX Handlers 4
WordPress Hooks 14
Maintenance & Trust
Live Demo Sandbox – Demo Site per Visitor Maintenance & Trust
Maintenance Signals
Community Trust
Live Demo Sandbox – Demo Site per Visitor Alternatives
Widget Instance
widget-instance
Display an active widget added to a sidebar within the editor or by using a shortcode, function or action.
Sandbox Payment Gateway for WooCommerce
sandbox-payment-gateway
Fake credit card and ACH/eCheck payment gateways for testing WooCommerce checkout flows.
Sandbox Site powered by Playground
playground
Short description Enables running a sandbox of your site using WordPress Playground (https://github.com/WordPress/wordpress-playground)
Multiple Ajax Calendar
multiple-ajax-calendar
The wordpress calendar widget enhanced to allow multiple instances of it in one page.
SiteSkite: Manage Multiple Sites, Maintenance, Backups, Updates, Sandbox, Monitoring & More
siteskite
Manage multiple WordPress sites from one dashboard. Automate backups, maintenance reports, updates, uptime monitoring, AI tools, Sandbox sites and mor …
Live Demo Sandbox – Demo Site per Visitor Developer Profile
3 plugins · 10 total installs
How We Detect Live Demo Sandbox – Demo Site per Visitor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/live-demo-sandbox/dist/admin-dashboard.js/wp-content/plugins/live-demo-sandbox/dist/libraries/translation-loader.js/wp-content/plugins/live-demo-sandbox/dist/admin-dashboard.js/wp-content/plugins/live-demo-sandbox/dist/libraries/translation-loader.jslive-demo-sandbox/admin-dashboard.js?ver=live-demo-sandbox/libraries/translation-loader.js?ver=HTML / DOM Fingerprints
id="Solidie_Sandbox_Backend_Dashboard"data-configsdata-hostsdata-meta_datawindow.slds_demo_user_auto_created<div
id="Solidie_Sandbox_Backend_Dashboard"data-configsdata-hostsdata-meta_data