Max Addons for Bricks Builder Security & Risk Analysis

wordpress.org/plugins/max-addons-for-bricks

Maximise your website building experience with the collection of useful and creative elements for Bricks Builder

1K active installs v1.6.7 PHP 7.4+ WP 6.3+ Updated Feb 20, 2026
addonsbricksbricks-addonbricks-builderelements
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Max Addons for Bricks Builder Safe to Use in 2026?

Generally Safe

Score 100/100

Max Addons for Bricks Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "max-addons-for-bricks" plugin v1.6.7 exhibits a strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events without authentication checks significantly limits its attack surface. Furthermore, the use of prepared statements for all SQL queries and a high percentage of properly escaped output suggest good development practices regarding data handling and injection prevention. The plugin also implements a reasonable number of nonce and capability checks, indicating an awareness of WordPress security mechanisms. The lack of any recorded CVEs or critical taint flows further reinforces its current secure state.

While the overall security is commendable, a minor concern arises from the presence of one external HTTP request, which, although not inherently insecure, warrants careful review to ensure it does not introduce any vulnerabilities related to data fetching or external service interaction. The absence of dangerous functions and file operations is also a positive indicator. Given the lack of known vulnerabilities and a minimal attack surface, the plugin appears well-maintained and secure at this version. The strengths lie in its limited entry points and robust data handling, with the primary area for continued vigilance being the single external HTTP request.

Key Concerns

  • External HTTP request detected
  • 88% output escaping, some outputs not escaped
Vulnerabilities
None known

Max Addons for Bricks Builder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Max Addons for Bricks Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
32
233 escaped
Nonce Checks
6
Capability Checks
5
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

88% escaped265 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
save_elements (classes\class-mab-admin-settings.php:438)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Max Addons for Bricks Builder Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actionplugins_loadedclasses\class-mab-admin-settings.php:36
actionplugins_loadedclasses\class-mab-admin-settings.php:38
actionadmin_menuclasses\class-mab-admin-settings.php:53
actionadmin_enqueue_scriptsclasses\class-mab-admin-settings.php:55
actionload-bricks_page_mab-settingsclasses\class-mab-admin-settings.php:56
actioninitclasses\class-mab-plugin.php:66
actionadmin_noticesclasses\class-mab-plugin.php:175
actionnetwork_admin_noticesclasses\class-mab-plugin.php:176
filterbricks/builder/i18nclasses\class-mab-plugin.php:198
filterbricks/element/set_root_attributesclasses\class-mab-plugin.php:199
actionwp_enqueue_scriptsclasses\class-mab-plugin.php:203
actionadmin_enqueue_scriptsincludes\admin\feedback\plugin-feedback.php:88
actionadmin_enqueue_scriptsincludes\admin\feedback\plugin-feedback.php:89
actionadmin_headincludes\admin\feedback\plugin-feedback.php:94
actionadmin_noticesincludes\admin\feedback\plugin-feedback.php:99
Maintenance & Trust

Max Addons for Bricks Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 20, 2026
PHP min version7.4
Downloads24K

Community Trust

Rating98/100
Number of ratings9
Active installs1K
Developer Profile

Max Addons for Bricks Builder Developer Profile

BloomPixel

4 plugins · 3K total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Max Addons for Bricks Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/max-addons-for-bricks/assets/css/admin-settings.css
Version Parameters
max-addons-for-bricks/assets/css/admin-settings.css?ver=

HTML / DOM Fingerprints

CSS Classes
mab-settings-form
Data Attributes
data-tab-content
JS Globals
MAB_Adminmab_admin_data
FAQ

Frequently Asked Questions about Max Addons for Bricks Builder