
Mesmerize Companion Security & Risk Analysis
wordpress.org/plugins/mesmerize-companionThe Mesmerize Companion plugin adds drag and drop page builder functionality to the Mesmerize theme.
Is Mesmerize Companion Safe to Use in 2026?
Generally Safe
Score 96/100Mesmerize Companion has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The mesmerizing-companion plugin v1.6.168 presents a mixed security posture. While the majority of SQL queries are properly prepared and most output is escaped, several areas raise concern. Specifically, three AJAX handlers lack authentication checks, creating a significant entry point for potential abuse. The presence of the `unserialize` function, though only one instance, is a known risk that could be exploited if user-supplied data is unserialized without proper sanitization.
The plugin's vulnerability history, with three past medium-severity CVEs, including Missing Authorization and Cross-site Scripting, is a notable concern. Although there are no currently unpatched vulnerabilities, the types of past issues align with some of the risks identified in the static analysis, particularly the missing authorization. The last vulnerability being in 2026 suggests an outdated security practice or a historical issue that, while patched, highlights previous weaknesses.
Overall, the plugin demonstrates some good security practices, but the unprotected AJAX endpoints and the history of critical vulnerability types warrant careful attention. The lack of critical or high-severity taint flows is a positive sign, but the static analysis findings and past CVEs suggest a need for continued vigilance and potential remediation.
Key Concerns
- Unprotected AJAX handlers
- Presence of unserialize function
- Past medium severity CVEs
- High percentage of SQL using prepared statements
- High percentage of properly escaped output
Mesmerize Companion Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Mesmerize Companion <= 1.6.158 - Missing Authorization Authenticated (Subscriber+) Settings Update
Mesmerize Companion <= 1.6.148 - Authenticated (Contributor+) Stored Cross-Site Scripting via mesmerize_contact_form Shortcode
Mesmerize Companion <= 1.6.133 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Mesmerize Companion Release Timeline
Mesmerize Companion Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Mesmerize Companion Attack Surface
AJAX Handlers 9
Shortcodes 2
WordPress Hooks 109
Maintenance & Trust
Mesmerize Companion Maintenance & Trust
Maintenance Signals
Community Trust
Mesmerize Companion Alternatives
Elementor Website Builder – more than just a page builder
elementor
The Elementor Website Builder has it all: drag and drop page builder, Atomic Editor, pixel perfect design, global and reusable style systems, mobile r …
Page Builder by SiteOrigin
siteorigin-panels
Build responsive page layouts using the widgets you know and love using this simple drag and drop page builder.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Beaver Builder Page Builder – Drag and Drop Website Builder
beaver-builder-lite-version
The Professional's Choice for Drag & Drop WordPress Page Building. Fast, Reliable, and Trusted since 2014.
Colibri Page Builder
colibri-page-builder
Colibri Page Builder adds drag and drop page builder functionality to the ColibriWP theme.
Mesmerize Companion Developer Profile
3 plugins · 76K total installs
How We Detect Mesmerize Companion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mesmerize-companion/support/wp-5.8.php/wp-content/plugins/mesmerize-companion/vendor/autoload.phpmesmerize-companion/version=HTML / DOM Fingerprints
mesmerize-companion-noticemesmerize-row-list-controlavailable-item-hover-buttonchecked-icondata-ajax-datadata-varnamedata-iddata-pro-onlydata-setting-linkmesmerize_content_list_control_l10n