OxyGridLayout by OxyNinja Security & Risk Analysis

wordpress.org/plugins/oxygridlayout-by-oxyninja

Simple grid layout for Oxygen Builder. Similar as you can find in Adobe XD/Sketch/Figma.

60 active installs v1.0.2 PHP 7.1+ WP 5.1+ Updated May 26, 2021
designgrid-layoutoxygen-builderoxyninja
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is OxyGridLayout by OxyNinja Safe to Use in 2026?

Generally Safe

Score 85/100

OxyGridLayout by OxyNinja has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The plugin 'oxygridlayout-by-oxyninja' v1.0.2 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified attack surface vectors like AJAX handlers, REST API routes, shortcodes, or cron events is a significant strength. Furthermore, the code signals indicate a clean codebase with no dangerous functions, file operations, or external HTTP requests. The robust use of prepared statements for SQL queries and high percentage of properly escaped output further bolster its security. The lack of any recorded vulnerabilities, including critical or high severity ones, suggests a mature development process and diligent security practices.

However, a notable concern is the complete absence of nonce and capability checks. While the current attack surface is zero, this leaves the plugin vulnerable should any new entry points be introduced in future versions without proper authentication and authorization mechanisms. The taint analysis also reported zero flows, which is positive but could also be an indicator of limited testing scope or a very simple plugin architecture. The overall conclusion is that this version is very secure due to its limited functionality and adherence to secure coding practices for existing features, but it lacks essential security layers that are standard for most WordPress plugins.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

OxyGridLayout by OxyNinja Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

OxyGridLayout by OxyNinja Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped12 total outputs
Attack Surface

OxyGridLayout by OxyNinja Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedcore\class-oxy-grid-layout.php:122
actionoxygen_enqueue_ui_scriptscore\includes\classes\class-oxy-grid-layout-run.php:53
actionadmin_menucore\includes\classes\class-oxy-grid-layout-run.php:54
actionadmin_initcore\includes\classes\class-oxy-grid-layout-run.php:55
Maintenance & Trust

OxyGridLayout by OxyNinja Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMay 26, 2021
PHP min version7.1
Downloads3K

Community Trust

Rating80/100
Number of ratings4
Active installs60
Developer Profile

OxyGridLayout by OxyNinja Developer Profile

Radoš

1 plugin · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect OxyGridLayout by OxyNinja

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/oxygridlayout-by-oxyninja/core/includes/assets/css/backend-styles-min.css/wp-content/plugins/oxygridlayout-by-oxyninja/core/includes/assets/js/backend-scripts-min.js
Script Paths
https://cdnjs.buymeacoffee.com/1.0.0/widget.prod.min.js
Version Parameters
oxygridlayout-by-oxyninja/core/includes/assets/css/backend-styles-min.css?ver=oxygridlayout-by-oxyninja/core/includes/assets/js/backend-scripts-min.js?ver=

HTML / DOM Fingerprints

JS Globals
ongridlayout
FAQ

Frequently Asked Questions about OxyGridLayout by OxyNinja