
Onex Custom Woo Builder Security & Risk Analysis
wordpress.org/plugins/onex-custom-woo-builderCustom Woo Builder is a plugin that allows creating WooCommerce Single Product page templates and WooCommerce Product Archive templates with Elementor …
Is Onex Custom Woo Builder Safe to Use in 2026?
Generally Safe
Score 85/100Onex Custom Woo Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "onex-custom-woo-builder" v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and implements a reasonable number of capability checks and nonce checks. It also avoids making external HTTP requests and does not bundle any known vulnerable libraries.
However, significant concerns arise from the static analysis. The plugin exposes a single AJAX handler that lacks any authentication checks, creating a direct and unprotected entry point for potential attackers. Furthermore, the taint analysis reveals two critical flows with unsanitized paths, indicating that user-supplied data is not being properly validated or neutralized, which could lead to serious vulnerabilities like arbitrary file read or code execution if these paths are exploitable. While there is no known vulnerability history, the presence of these critical taint flows in the current version is a strong indicator of potential risk.
In conclusion, despite the absence of recorded CVEs and the use of prepared statements, the unprotected AJAX handler and the critical taint analysis findings present a notable security risk. The plugin needs immediate attention to address these critical flaws to improve its overall security. The lack of historical vulnerabilities is a positive sign, but it doesn't negate the immediate risks identified in the code.
Key Concerns
- Unprotected AJAX handler
- Critical taint flow with unsanitized paths (x2)
- Significant portion of output not properly escaped
Onex Custom Woo Builder Security Vulnerabilities
Onex Custom Woo Builder Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Onex Custom Woo Builder Attack Surface
AJAX Handlers 1
WordPress Hooks 80
Maintenance & Trust
Onex Custom Woo Builder Maintenance & Trust
Maintenance Signals
Community Trust
Onex Custom Woo Builder Alternatives
Custom Builder for Elementor and WooCommerce
custom-woo-builder-for-elementor
Custom Woo Builder is a plugin that allows creating WooCommerce Single Product page templates and WooCommerce Product Archive templates with Elementor …
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
premium-addons-for-elementor
Elementor Carousel, Mega Menu, Posts List/Slider, Media Gallery, WooCommerce Widgets, Display Conditions, Premade Templates & more.
Onex Custom Woo Builder Developer Profile
8 plugins · 440 total installs
How We Detect Onex Custom Woo Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/onex-custom-woo-builder/assets/css/admin.css/wp-content/plugins/onex-custom-woo-builder/assets/css/frontend.css/wp-content/plugins/onex-custom-woo-builder/assets/js/admin.js/wp-content/plugins/onex-custom-woo-builder/assets/js/frontend.js/wp-content/plugins/onex-custom-woo-builder/framework/interface-builder/assets/css/editor.css/wp-content/plugins/onex-custom-woo-builder/framework/interface-builder/assets/js/editor.js/wp-content/plugins/onex-custom-woo-builder/assets/js/admin.js/wp-content/plugins/onex-custom-woo-builder/assets/js/frontend.js/wp-content/plugins/onex-custom-woo-builder/framework/interface-builder/assets/js/editor.jsonex-custom-woo-builder/assets/css/admin.css?ver=onex-custom-woo-builder/assets/css/frontend.css?ver=onex-custom-woo-builder/assets/js/admin.js?ver=onex-custom-woo-builder/assets/js/frontend.js?ver=onex-custom-woo-builder/framework/interface-builder/assets/css/editor.css?ver=onex-custom-woo-builder/framework/interface-builder/assets/js/editor.js?ver=HTML / DOM Fingerprints
custom-woo-builder-editorcustom-woo-builder-content<!-- Onex Custom Woo Builder --><!-- custom-woo-builder elementor template -->data-custom-woo-builder-idcustom_woo_builder_frontend_dataCustomWooBuilderEditor/wp-json/custom-woo-builder/v1/get-template-content[custom_woo_builder_template