
Omnipress Security & Risk Analysis
wordpress.org/plugins/omnipressA powerful Gutenberg plugin with pre-built patterns, advanced blocks, and demo sites to speed up website creation using Full Site Editing.
Is Omnipress Safe to Use in 2026?
Use With Caution
Score 50/100Omnipress has 2 unpatched vulnerabilities. Evaluate alternatives or apply available mitigations.
The omnipress plugin v1.6.7 presents a mixed security posture. On the positive side, the plugin demonstrates good practices in several areas, including 100% of SQL queries using prepared statements, a high percentage of properly escaped output, and a substantial number of nonce and capability checks, indicating an awareness of common WordPress security vulnerabilities. However, significant concerns are raised by the presence of unprotected entry points and historical vulnerability patterns.
The static analysis reveals one unprotected REST API route, which is a critical entry point that could be exploited without proper authorization checks. While taint analysis shows no critical or high-severity unsanitized flows, the presence of 5 flows with unsanitized paths, even if categorized as lower severity, warrants attention as potential avenues for exploitation. The plugin also performs a considerable number of file operations and external HTTP requests, which, if not handled securely, could introduce risks.
The vulnerability history is a major red flag. With 6 known CVEs, 2 of which are currently unpatched, and a history including high and medium severity vulnerabilities like PHP Remote File Inclusion, Cross-site Scripting, and Authorization Bypass, the plugin has a proven track record of exploitable weaknesses. The recurrence of specific vulnerability types suggests systemic issues in code sanitization and access control. While the last vulnerability was in 2026 (a future date, likely a typo in the provided data, but assuming it reflects past activity), the existence of unpatched vulnerabilities is a severe risk. The plugin's strengths in prepared statements and output escaping are overshadowed by the historical prevalence of vulnerabilities and the identified unprotected entry point, suggesting a high overall risk for sites using this version.
Key Concerns
- Unprotected REST API route
- Unpatched CVEs (2 total)
- High number of CVEs (6 total)
- History of high/medium severity vulns
- Flows with unsanitized paths (5)
Omnipress Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
Omnipress <= 1.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
Omnipress <= 1.6.7 - Authenticated (Contributor+) Local File Inclusion
Omnipress <= 1.6.5 - Authenticated (Author+) Stored Cross-Site Scripting
Omnipress <= 1.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Omnipress <= 1.5.4 - Authenticated (Contributor+) Post Disclosure
Omnipress <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Omnipress Release Timeline
Omnipress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Omnipress Attack Surface
AJAX Handlers 4
REST API Routes 1
WordPress Hooks 71
Maintenance & Trust
Omnipress Maintenance & Trust
Maintenance Signals
Community Trust
Omnipress Alternatives
Greenshift – animation and page builder blocks
greenshift-animation-and-page-builder-blocks
More than 20 special blocks for Gutenberg to build complex pages and animations with highest possible web vitals score.
Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates
cozy-addons
Build any WordPress site without Elementor or Divi. 57 Gutenberg blocks, 600+ ready-made patterns & 40+ FSE templates. No page builder needed.
Nova Blocks by Pixelgrade
nova-blocks
A collection of distinctive Gutenberg blocks, committed to making your site shine like a newborn star.
Advanced Block Controls (ABC) — Core Blocks Page Builder and Full Site Editing Toolkit
advanced-block-controls
Enhancing core Gutenberg blocks with advanced page builder controls, eliminating the need for third-party blocks to build professional websites.
Gutenwave Blocks – Gutenberg Page Builder Blocks for Block Editor & FSE
gutenwave-blocks
Build stunning websites with Gutenberg. Free responsive blocks, starter templates & full site editing support in one lightweight plugin.
Omnipress Developer Profile
8 plugins · 1K total installs
How We Detect Omnipress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/omnipress/assets/css/main.css/wp-content/plugins/omnipress/assets/css/responsive.css/wp-content/plugins/omnipress/assets/js/omnipress-scripts.js/wp-content/plugins/omnipress/assets/js/main.js/wp-content/plugins/omnipress/assets/js/omnipress-scripts.js/wp-content/plugins/omnipress/assets/js/main.jsomnipress/assets/css/main.css?ver=omnipress/assets/css/responsive.css?ver=omnipress/assets/js/omnipress-scripts.js?ver=omnipress/assets/js/main.js?ver=HTML / DOM Fingerprints
omnipress-sectionomnipress-blockomnipress-popup-builderdata-omnipress-delaydata-omnipress-triggerdata-omnipress-positiondata-omnipress-repetitionOmnipressCoreOmnipressPopupBuilder