Octonis Page Builder Security & Risk Analysis

wordpress.org/plugins/octonis-page-builder

Build amazing web pages or website without any programming skills. Just choose and customize blocks. Focus on the goal, not on technical issues .

10 active installs v1.0.6 PHP + WP + Updated Mar 21, 2016
builderdrag-and-drop-builderlayout-builderpage-builderwebsite-builder
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Octonis Page Builder Safe to Use in 2026?

Generally Safe

Score 85/100

Octonis Page Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'octonis-page-builder' v1.0.6 plugin exhibits a mixed security posture. On one hand, the static analysis reveals an extremely small attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication. This is a strong positive indicator of secure design at the entry point level.

However, significant concerns arise from the code signals. The presence of two instances of the `unserialize` function is a critical risk, as it can lead to remote code execution if untrusted data is passed to it. Coupled with a concerningly low rate of output escaping (only 8% properly escaped), there is a substantial risk of cross-site scripting (XSS) vulnerabilities. While the vulnerability history is clean, the code signals suggest potential latent issues that have not yet manifested as public CVEs or have been missed by previous analyses.

The plugin's clean vulnerability history is a positive, indicating past development diligence or perhaps a lack of widespread targeting. Nonetheless, the identified dangerous functions and poor output escaping practices present immediate, exploitable risks that outweigh the current lack of reported vulnerabilities. A proactive approach to address these code-level weaknesses is strongly recommended.

Key Concerns

  • Dangerous unserialize function found
  • Low percentage of properly escaped output
  • Low rate of prepared statements in SQL queries
Vulnerabilities
None known

Octonis Page Builder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Octonis Page Builder Code Analysis

Dangerous Functions
2
Raw SQL Queries
7
5 prepared
Unescaped Output
178
15 escaped
Nonce Checks
2
Capability Checks
1
File Operations
35
External Requests
3
Bundled Libraries
2

Dangerous Functions Found

unserializereturn $safe ? @unserialize($data) : unserialize($data);classes\utils.php:14
unserializereturn $safe ? @unserialize($data) : unserialize($data);classes\utils.php:14

Bundled Libraries

jQueryTinyMCE1.0

SQL Query Safety

42% prepared12 total queries

Output Escaping

8% escaped193 total outputs
Attack Surface

Octonis Page Builder Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionadmin_noticesclasses\errors.php:43
filterthe_contentclasses\errors.php:45
actioninitclasses\frame.php:113
actioninitclasses\frame.php:114
actioninitclasses\frame.php:119
actionactivated_pluginclasses\modInstaller.php:120
actionactivated_pluginclasses\utils.php:311
actionadmin_menumodules\adminmenu\mod.php:7
filterwp_mail_content_typemodules\mail\mod.php:18
actiontemplate_redirectmodules\octo\mod.php:7
actionadd_meta_boxesmodules\octo\mod.php:9
filterposts_join_requestmodules\octo\models\octo.php:149
filterposts_where_requestmodules\octo\models\octo.php:150
filterposts_fields_requestmodules\octo\models\octo.php:151
actionadmin_footermodules\supsystic_promo\mod.php:15
actionadmin_enqueue_scriptsmodules\templates\mod.php:12
Maintenance & Trust

Octonis Page Builder Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedMar 21, 2016
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Octonis Page Builder Developer Profile

octonis

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Octonis Page Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/octonis-page-builder/modules/oct_content/static/css/oct_content.css/wp-content/plugins/octonis-page-builder/modules/oct_content/static/js/oct_content.js/wp-content/plugins/octonis-page-builder/modules/oct_builder/static/css/oct_builder.css/wp-content/plugins/octonis-page-builder/modules/oct_builder/static/js/oct_builder.js/wp-content/plugins/octonis-page-builder/modules/oct_header/static/css/oct_header.css/wp-content/plugins/octonis-page-builder/modules/oct_header/static/js/oct_header.js/wp-content/plugins/octonis-page-builder/modules/oct_services/static/css/oct_services.css/wp-content/plugins/octonis-page-builder/modules/oct_services/static/js/oct_services.js+70 more
Script Paths
/wp-content/plugins/octonis-page-builder/octonis-page-builder.php
Version Parameters
octonis-page-builder/modules/oct_content/static/css/oct_content.css?ver=octonis-page-builder/modules/oct_content/static/js/oct_content.js?ver=octonis-page-builder/modules/oct_builder/static/css/oct_builder.css?ver=octonis-page-builder/modules/oct_builder/static/js/oct_builder.js?ver=octonis-page-builder/modules/oct_header/static/css/oct_header.css?ver=octonis-page-builder/modules/oct_header/static/js/oct_header.js?ver=octonis-page-builder/modules/oct_services/static/css/oct_services.css?ver=octonis-page-builder/modules/oct_services/static/js/oct_services.js?ver=octonis-page-builder/modules/oct_testimonial/static/css/oct_testimonial.css?ver=octonis-page-builder/modules/oct_testimonial/static/js/oct_testimonial.js?ver=octonis-page-builder/modules/oct_accordion/static/css/oct_accordion.css?ver=octonis-page-builder/modules/oct_accordion/static/js/oct_accordion.js?ver=octonis-page-builder/modules/oct_gallery/static/css/oct_gallery.css?ver=octonis-page-builder/modules/oct_gallery/static/js/oct_gallery.js?ver=octonis-page-builder/modules/oct_button/static/css/oct_button.css?ver=octonis-page-builder/modules/oct_button/static/js/oct_button.js?ver=octonis-page-builder/modules/oct_tabs/static/css/oct_tabs.css?ver=octonis-page-builder/modules/oct_tabs/static/js/oct_tabs.js?ver=octonis-page-builder/modules/oct_menu/static/css/oct_menu.css?ver=octonis-page-builder/modules/oct_menu/static/js/oct_menu.js?ver=octonis-page-builder/modules/oct_price_table/static/css/oct_price_table.css?ver=octonis-page-builder/modules/oct_price_table/static/js/oct_price_table.js?ver=octonis-page-builder/modules/oct_contact_form/static/css/oct_contact_form.css?ver=octonis-page-builder/modules/oct_contact_form/static/js/oct_contact_form.js?ver=octonis-page-builder/modules/oct_map/static/css/oct_map.css?ver=octonis-page-builder/modules/oct_map/static/js/oct_map.js?ver=octonis-page-builder/modules/oct_countdown/static/css/oct_countdown.css?ver=octonis-page-builder/modules/oct_countdown/static/js/oct_countdown.js?ver=octonis-page-builder/modules/oct_slider/static/css/oct_slider.css?ver=octonis-page-builder/modules/oct_slider/static/js/oct_slider.js?ver=octonis-page-builder/modules/oct_recent_posts/static/css/oct_recent_posts.css?ver=octonis-page-builder/modules/oct_recent_posts/static/js/oct_recent_posts.js?ver=octonis-page-builder/modules/oct_divider/static/css/oct_divider.css?ver=octonis-page-builder/modules/oct_divider/static/js/oct_divider.js?ver=octonis-page-builder/modules/oct_separator/static/css/oct_separator.css?ver=octonis-page-builder/modules/oct_separator/static/js/oct_separator.js?ver=octonis-page-builder/modules/oct_html/static/css/oct_html.css?ver=octonis-page-builder/modules/oct_html/static/js/oct_html.js?ver=octonis-page-builder/modules/oct_image/static/css/oct_image.css?ver=octonis-page-builder/modules/oct_image/static/js/oct_image.js?ver=octonis-page-builder/modules/oct_video/static/css/oct_video.css?ver=octonis-page-builder/modules/oct_video/static/js/oct_video.js?ver=octonis-page-builder/modules/oct_heading/static/css/oct_heading.css?ver=octonis-page-builder/modules/oct_heading/static/js/oct_heading.js?ver=octonis-page-builder/modules/oct_list/static/css/oct_list.css?ver=octonis-page-builder/modules/oct_list/static/js/oct_list.js?ver=octonis-page-builder/modules/oct_blog/static/css/oct_blog.css?ver=octonis-page-builder/modules/oct_blog/static/js/oct_blog.js?ver=octonis-page-builder/modules/oct_post_slider/static/css/oct_post_slider.css?ver=octonis-page-builder/modules/oct_post_slider/static/js/oct_post_slider.js?ver=octonis-page-builder/modules/oct_products/static/css/oct_products.css?ver=octonis-page-builder/modules/oct_products/static/js/oct_products.js?ver=octonis-page-builder/modules/oct_product_slider/static/css/oct_product_slider.css?ver=octonis-page-builder/modules/oct_product_slider/static/js/oct_product_slider.js?ver=octonis-page-builder/modules/oct_woo_products/static/css/oct_woo_products.css?ver=octonis-page-builder/modules/oct_woo_products/static/js/oct_woo_products.js?ver=octonis-page-builder/modules/oct_woo_product_slider/static/css/oct_woo_product_slider.css?ver=octonis-page-builder/modules/oct_woo_product_slider/static/js/oct_woo_product_slider.js?ver=octonis-page-builder/modules/oct_single_product/static/css/oct_single_product.css?ver=octonis-page-builder/modules/oct_single_product/static/js/oct_single_product.js?ver=octonis-page-builder/modules/oct_forms/static/css/oct_forms.css?ver=octonis-page-builder/modules/oct_forms/static/js/oct_forms.js?ver=octonis-page-builder/modules/oct_page_title/static/css/oct_page_title.css?ver=octonis-page-builder/modules/oct_page_title/static/js/oct_page_title.js?ver=octonis-page-builder/modules/oct_row/static/css/oct_row.css?ver=octonis-page-builder/modules/oct_row/static/js/oct_row.js?ver=octonis-page-builder/modules/oct_column/static/css/oct_column.css?ver=octonis-page-builder/modules/oct_column/static/js/oct_column.js?ver=octonis-page-builder/modules/oct_section/static/css/oct_section.css?ver=octonis-page-builder/modules/oct_section/static/js/oct_section.js?ver=octonis-page-builder/modules/oct_button_new/static/css/oct_button_new.css?ver=octonis-page-builder/modules/oct_button_new/static/js/oct_button_new.js?ver=octonis-page-builder/modules/oct_section_new/static/css/oct_section_new.css?ver=octonis-page-builder/modules/oct_section_new/static/js/oct_section_new.js?ver=octonis-page-builder/modules/oct_row_new/static/css/oct_row_new.css?ver=octonis-page-builder/modules/oct_row_new/static/js/oct_row_new.js?ver=octonis-page-builder/modules/oct_column_new/static/css/oct_column_new.css?ver=octonis-page-builder/modules/oct_column_new/static/js/oct_column_new.js?ver=

HTML / DOM Fingerprints

CSS Classes
oct-sectionoct-rowoct-columnoct-module
Data Attributes
data-oct-iddata-oct-type
JS Globals
octCurConfig
FAQ

Frequently Asked Questions about Octonis Page Builder