Page builder for Posts – Mong9 Editor Security & Risk Analysis

wordpress.org/plugins/mong9-editor

The most advanced frontend drag & drop content editor. Mong9 Editor is a responsive page builder which can be used to extend the Classic Editor.

10 active installs v1.1.1 PHP 5.3+ WP 4.9+ Updated Jun 25, 2019
drag-and-dropeditorelementorlanding-pagepage-builder
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Page builder for Posts – Mong9 Editor Safe to Use in 2026?

Generally Safe

Score 85/100

Page builder for Posts – Mong9 Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The mong9-editor plugin version 1.1.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and shows a commitment to capability checks, which are present in a reasonable number. The absence of known CVEs in its history is also a positive indicator of past security diligence or a lack of focus from attackers. However, the plugin introduces significant risks through its attack surface. With three AJAX handlers, two of which lack proper authentication checks, there's a clear pathway for unauthenticated users to interact with potentially sensitive functionalities. The taint analysis, while not revealing critical or high severity issues, did identify three flows with unsanitized paths, indicating potential for unexpected behavior or exploitation if these paths are ever exposed to malicious input. The low percentage of properly escaped output (25%) is a significant concern, suggesting a high likelihood of cross-site scripting (XSS) vulnerabilities that could be leveraged by attackers. While the plugin has no recorded vulnerabilities, the identified weaknesses in its attack surface and output sanitization suggest a latent risk that could be exploited.

Key Concerns

  • Unprotected AJAX handlers
  • Flows with unsanitized paths identified
  • Low percentage of properly escaped output
Vulnerabilities
None known

Page builder for Posts – Mong9 Editor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Page builder for Posts – Mong9 Editor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
1 escaped
Nonce Checks
2
Capability Checks
5
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

25% escaped4 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

5 flows3 with unsanitized paths
mong9editor_ajax_callback_get_video_url (includes\editor-function.php:92)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Page builder for Posts – Mong9 Editor Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 3

authwp_ajax_get_exampleincludes\editor-function.php:13
authwp_ajax_mong9_editor_upload_imageincludes\editor-function.php:15
authwp_ajax_get_video_urlincludes\editor-function.php:90
WordPress Hooks 7
filterquery_varsincludes\editor-function.php:8
actionparse_requestincludes\editor-function.php:10
actionadmin_enqueue_scriptsincludes\in-post.php:4
actionadmin_initincludes\in-post.php:24
actioninitmong9-editor.php:38
actionwp_enqueue_scriptsmong9-editor.php:53
filterthe_contentmong9-editor.php:59
Maintenance & Trust

Page builder for Posts – Mong9 Editor Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJun 25, 2019
PHP min version5.3
Downloads4K

Community Trust

Rating100/100
Number of ratings4
Active installs10
Developer Profile

Page builder for Posts – Mong9 Editor Developer Profile

mong9

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Page builder for Posts – Mong9 Editor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mong9-editor/javascript/etc/webtookit.openwindow.js/wp-content/plugins/mong9-editor/javascript/mong9.js/wp-content/plugins/mong9-editor/javascript/editor/mode-obj.js/wp-content/plugins/mong9-editor/etc/axicon/axicon.min.css/wp-content/plugins/mong9-editor/css/mong9-base.css/wp-content/plugins/mong9-editor/css/mong9-user.css/wp-content/plugins/mong9-editor/css/mong9-w.css/wp-content/plugins/mong9-editor/css/mong9-m.css+8 more
Script Paths
/wp-content/plugins/mong9-editor/javascript/etc/webtookit.openwindow.js/wp-content/plugins/mong9-editor/javascript/mong9.js/wp-content/plugins/mong9-editor/javascript/editor/mode-obj.js/wp-content/plugins/mong9-editor/javascript/mong9-utils.js/wp-content/plugins/mong9-editor/javascript/layer-func2.js/wp-content/plugins/mong9-editor/javascript/m9ani.js+2 more

HTML / DOM Fingerprints

CSS Classes
m9-contentsm9editor-layoutm9_editor_boxm9editor-layout center
HTML Comments
// Mong9 Editor ////m9_font_family(XXX1,XXX2,XXX3)//
Data Attributes
alt_no
JS Globals
EHASH_SETmong9_ajax_blockmong9_ajax_uploadmong9_ajax_videom9_editor
REST Endpoints
/wp-json/mong9_editor_block/get_example/wp-json/mong9_editor_upload/mong9_editor_upload_image/wp-json/mong9_editor_video/get_video_url
FAQ

Frequently Asked Questions about Page builder for Posts – Mong9 Editor