
Mixmat Security & Risk Analysis
wordpress.org/plugins/mixmatMixmat Page Mixer gives editors an easy way to sectionalize the posts and pages without knowing CSS or HTML.
Is Mixmat Safe to Use in 2026?
Generally Safe
Score 85/100Mixmat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mixmat" plugin v1.0.63 demonstrates a generally positive security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are strong indicators of secure coding practices. The fact that all SQL queries utilize prepared statements is a significant strength, mitigating the risk of SQL injection vulnerabilities. Furthermore, the plugin has no recorded vulnerability history, which suggests a history of stable and secure development.
However, there are areas for concern. A notable weakness is the complete lack of nonce checks and capability checks across all identified entry points, which include 12 shortcodes. This absence creates a significant risk, as these entry points are effectively unprotected against various injection and unauthorized action vulnerabilities. While the taint analysis reported no issues, the lack of robust authentication and authorization mechanisms means that malicious inputs could potentially still lead to unexpected behavior or data manipulation, especially if new vulnerabilities are introduced in future updates. The output escaping is also only moderately effective, with 38% of outputs not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities.
In conclusion, while the "mixmat" plugin exhibits several commendable security features and a clean vulnerability history, the critical absence of nonce and capability checks on its numerous shortcode entry points, coupled with incomplete output escaping, presents a substantial security risk. Developers should prioritize implementing these fundamental security checks to harden the plugin against common web attack vectors.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Incomplete output escaping
Mixmat Security Vulnerabilities
Mixmat Code Analysis
Output Escaping
Mixmat Attack Surface
Shortcodes 12
WordPress Hooks 12
Maintenance & Trust
Mixmat Maintenance & Trust
Maintenance Signals
Community Trust
Mixmat Alternatives
D-Elementor-widgets
d-elementor-widgets
D-Elementor-Widgets Addon comes with widgets and extensions to extend the power of Elementor Page Builder.
Divein Builder
divein-builder
Advanced drag and drop page builder plugin. Create pages and posts visually with any theme, any template, any design.
Elementor Website Builder – More Than Just a Page Builder
elementor
The Elementor Website Builder has it all: drag and drop page builder, pixel perfect design, mobile responsive editing, and more. Get started now!
Page Builder by SiteOrigin
siteorigin-panels
Build responsive page layouts using the widgets you know and love using this simple drag and drop page builder.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Mixmat Developer Profile
17 plugins · 2K total installs
How We Detect Mixmat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mixmat/css/mixmat-style.css/wp-content/plugins/mixmat/js/mixmat-plugin.jsmixmat-stylemixmat-plugin.js?ver=1.0.63HTML / DOM Fingerprints
mixmat_pluginPage_sectionmixmat_settings[mixmat_color_field_0]mixmat_settings[mixmat_color_field_1]mixmat_settings[mixmat_theme_adjustment_option]mixmat_settings[mixmat_theme_margins_option][one][one_half][one_fourth][one_third]