
Mega Addons For WPBakery Page Builder Security & Risk Analysis
wordpress.org/plugins/mega-addons-for-visual-composer34+ Addons WPBakery extension, Beautifully designed unique elements, Includes Premium quality addons For WPBakery Page Builder.
Is Mega Addons For WPBakery Page Builder Safe to Use in 2026?
High Risk
Score 41/100Mega Addons For WPBakery Page Builder carries significant security risk with 3 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The "mega-addons-for-visual-composer" plugin v4.3.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices in handling SQL queries using prepared statements and has a very high percentage of properly escaped output. It also reports no dangerous function usage, file operations, or external HTTP requests, and no bundled libraries, which are all favorable security indicators. However, significant concerns arise from the analysis of its entry points and vulnerability history. The presence of one unprotected AJAX handler creates a direct attack vector. While taint analysis did not reveal critical or high severity unsanitized paths, the lack of nonce checks on the identified AJAX handler is a serious omission that could lead to Cross-Site Request Forgery (CSRF) attacks. The plugin's vulnerability history is a major red flag, with 3 known CVEs, 2 of which are currently unpatched and categorized as high severity. These historical vulnerabilities include Cross-site Scripting, Missing Authorization, and CSRF, which directly align with the potential risks identified in the code analysis. The persistent occurrence of these vulnerability types suggests a recurring pattern of insecure coding practices, particularly around input validation and authorization. Despite some strengths in data handling, the presence of unpatched high-severity vulnerabilities and an unprotected entry point makes this plugin a substantial risk.
Key Concerns
- Unprotected AJAX handler detected
- Missing nonce checks on AJAX handler
- 2 unpatched high severity CVEs
- 1 medium severity CVE
- Vulnerability history includes XSS, Missing Auth, CSRF
Mega Addons For WPBakery Page Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Mega Addons For WPBakery Page Builder <= 4.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Mega Addons For WPBakery Page Builder <= 4.3.0 - Authenticated (Subscriber+) Settings Update
Mega Addons For WPBakery Page Builder <= 4.2.7 - Cross-Site Request Forgery to Settings Update
Mega Addons For WPBakery Page Builder Release Timeline
Mega Addons For WPBakery Page Builder Code Analysis
Output Escaping
Data Flow Analysis
Mega Addons For WPBakery Page Builder Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
Mega Addons For WPBakery Page Builder Maintenance & Trust
Maintenance Signals
Community Trust
Mega Addons For WPBakery Page Builder Alternatives
Post Slider For WPBakery Page Builder
post-carousel-slider-for-visual-composer
Drag & touch Post Carousel anything at any position (row / column) in VC
Image Hover Effects for Visual Composer
image-hover-effect-for-visual-composer
Requires at least: 3.5 Tested up to: 4.9 Stable tag: 1.0 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.
Twenty20 Image Before-After
twenty20
Professional before & after image comparison slider for WordPress. Create engaging visual comparisons with an intuitive drag & drop interface.
Video Background
video-background
Easily assign a video background to any element on your WordPress pages or posts. Now compatible with WPBakery (Visual Composer) and SiteOrigin Page B …
WPMasterToolKit (WPMTK) – All in one plugin
wpmastertoolkit
Duplicate post, post order, email via SMTP, code snippets, disable gutenberg, child theme generator, svg support, disable XMLRPC, and more...
Mega Addons For WPBakery Page Builder Developer Profile
4 plugins · 32K total installs
How We Detect Mega Addons For WPBakery Page Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mega-addons-for-visual-composer/css/ihover.css/wp-content/plugins/mega-addons-for-visual-composer/css/style.css/wp-content/plugins/mega-addons-for-visual-composer/css/font-awesome/css/all.css/wp-content/plugins/mega-addons-for-visual-composer/lib/style.css/wp-content/plugins/mega-addons-for-visual-composer/lib/admin.css/wp-content/plugins/mega-addons-for-visual-composer/lib/admin.js/wp-content/plugins/mega-addons-for-visual-composer/lib/admin.jsHTML / DOM Fingerprints
addons-admin-wrapmega-addons-versionvc-heading-titlemega-addons-titlevc-heading-iconThis program is free software; you can redistribute it and/or modifyYou should have received a copy of the GNU General Public License<!-- VC Background -->data-vc-shortcode-contentdata-hide-on-mobiledata-hide-on-desktopwindow.vc_mega_addons_params[vc_row][vc_column][vc_btn][vc_icon]