
Livemesh SiteOrigin Widgets Security & Risk Analysis
wordpress.org/plugins/livemesh-siteorigin-widgetsA collection of premium quality widgets for use in any widgetized area or in SiteOrigin page builder. SiteOrigin Widgets Bundle is required.
Is Livemesh SiteOrigin Widgets Safe to Use in 2026?
Generally Safe
Score 96/100Livemesh SiteOrigin Widgets has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "livemesh-siteorigin-widgets" v3.9.2 exhibits a mixed security posture. On the positive side, all SQL queries are properly prepared, and there are no detected dangerous functions or file operations, indicating a generally good approach to core security practices. However, a significant concern is the presence of one AJAX handler without any authentication checks, creating a direct, unprotected entry point for potential attackers. While taint analysis found no immediate vulnerabilities, the historical data reveals two previous CVEs, including a high-severity Cross-Site Scripting (XSS) vulnerability and a Missing Authorization issue. The fact that these have been patched is a good sign, but the pattern suggests that past vulnerabilities have been present and addressed, highlighting a need for continued vigilance and robust security practices.
Key Concerns
- AJAX handler without auth checks
- Output escaping only 58% proper
- Total known CVEs (2)
- High severity historical CVE (1)
- Bundled Freemius v1.0 library
Livemesh SiteOrigin Widgets Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Livemesh SiteOrigin Widgets <= 3.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Hero Header and Pricing Table Widgets
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
Livemesh SiteOrigin Widgets Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Livemesh SiteOrigin Widgets Attack Surface
AJAX Handlers 1
WordPress Hooks 25
Maintenance & Trust
Livemesh SiteOrigin Widgets Maintenance & Trust
Maintenance Signals
Community Trust
Livemesh SiteOrigin Widgets Alternatives
RA Widgets Bundle
ra-widgets-bundle
A collection of widgets using the SiteOrigin Widgets API.
WP-Stateless – SiteOrigin Widgets Bundle Addon
wp-stateless-siteorigin-widgets-bundle-addon
Provides compatibility between the SiteOrigin Widgets Bundle and the WP-Stateless plugins.
Ultimate Addons for SiteOrigin
addon-so-widgets-bundle
An ultimate collection of addons for SiteOrigin. SiteOrigin Widgets Bundle is required.
Tabs Widget for Page Builder
tabs-widget-for-page-builder
Adds a "Tabs for Page Builder" widget, which can be used in Page Builder by SiteOrigin editor.
Zen Addons for SiteOrigin Page Builder
zen-addons-for-siteorigin-page-builder
Zen Addons is a collection of helpful widget extensions for SiteOrigin Page Builder. It's simple, flexible, and useful.
Livemesh SiteOrigin Widgets Developer Profile
8 plugins · 81K total installs
How We Detect Livemesh SiteOrigin Widgets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/livemesh-siteorigin-widgets/assets/css/lsow-frontend.css/wp-content/plugins/livemesh-siteorigin-widgets/assets/js/lsow-frontend.js/wp-content/plugins/livemesh-siteorigin-widgets/includes/widgets/premium/woo-products/css/style.css/wp-content/plugins/livemesh-siteorigin-widgets/includes/widgets/premium/woo-products/js/scripts.js/wp-content/plugins/livemesh-siteorigin-widgets/includes/widgets/premium/woo-products/css/frontend.css/wp-content/plugins/livemesh-siteorigin-widgets/includes/widgets/premium/woo-products/js/frontend.js/wp-content/plugins/livemesh-siteorigin-widgets/assets/css/lsow-admin.css/wp-content/plugins/livemesh-siteorigin-widgets/assets/js/lsow-admin.js+108 more/wp-content/plugins/livemesh-siteorigin-widgets/assets/js/lsow-frontend.js/wp-content/plugins/livemesh-siteorigin-widgets/includes/widgets/premium/woo-products/js/scripts.js/wp-content/plugins/livemesh-siteorigin-widgets/includes/widgets/premium/woo-products/js/frontend.js/wp-content/plugins/livemesh-siteorigin-widgets/assets/js/lsow-admin.js/wp-content/plugins/livemesh-siteorigin-widgets/includes/widgets/premium/fancy-heading/js/scripts.js/wp-content/plugins/livemesh-siteorigin-widgets/includes/widgets/premium/fancy-heading/js/frontend.js+52 morelivemesh-siteorigin-widgets/assets/css/lsow-frontend.css?ver=livemesh-siteorigin-widgets/assets/js/lsow-frontend.js?ver=livemesh-siteorigin-widgets/assets/css/lsow-admin.css?ver=livemesh-siteorigin-widgets/assets/js/lsow-admin.js?ver=HTML / DOM Fingerprints
lsow-feature-listlsow-post-gridlsow-post-carousellsow-pricing-tablelsow-pricing-table-altlsow-woo-productslsow-accordionslsow-tabs+19 more<!-- livemesh-so-widgets -->data-lsow-optionswindow.lsow_fslsow_admin_ajaxlsow_admin_nonce