
Pearl – Header Builder Security & Risk Analysis
wordpress.org/plugins/pearl-header-builderPearl Header Builder gives you complete freedom to compose a header that perfectly suits your site.
Is Pearl – Header Builder Safe to Use in 2026?
Generally Safe
Score 97/100Pearl – Header Builder has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'pearl-header-builder' plugin, version 1.3.13, demonstrates a generally good security posture based on the static analysis. It avoids dangerous functions, file operations, and external HTTP requests. Notably, all SQL queries are prepared, and the vast majority of output is properly escaped, indicating a strong adherence to secure coding practices. The presence of nonce and capability checks on entry points is also a positive sign for protecting against common web attacks.
Despite the positive static analysis, the plugin's vulnerability history is a significant concern. It has a history of six known medium-severity vulnerabilities, including Cross-Site Request Forgery, Missing Authorization, and Cross-Site Scripting. While none are currently unpatched, this pattern suggests recurring security weaknesses that require diligent oversight. The last reported vulnerability was very recent, implying that these issues may not be fully resolved and could resurface.
In conclusion, while the current version shows improvements in its code, the plugin's past vulnerability trends warrant caution. Users should remain vigilant, ensure regular updates, and be aware of the potential for previously exploited vulnerability types to reappear. The plugin has strengths in its current code but a significant weakness in its historical security record.
Key Concerns
- 6 known medium severity vulnerabilities historically
- Recent vulnerability (2025-04-01)
- 6 AJAX handlers with 0 unprotected
- 94% output escaping (3% deduction for the 6% unescaped)
Pearl – Header Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
Pearl <= 1.3.9 - Cross-Site Request Forgery
Pearl <= 1.3.9 - Missing Authorization
Wordpress Header Builder Plugin <= 1.3.8 - Cross-Site Request Forgery to Header Deletion
WordPress Header Builder Plugin – Pearl <= 1.3.7 - Missing Authorization to Unauthenticated Arbitrary Site Options Deletion
WordPress Header Builder Plugin – Pearl <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Pearl <= 1.3.4 - Cross-Site Request Forgery via stm_save_hb_settings
Pearl – Header Builder Release Timeline
Pearl – Header Builder Code Analysis
Output Escaping
Data Flow Analysis
Pearl – Header Builder Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Pearl – Header Builder Maintenance & Trust
Maintenance Signals
Community Trust
Pearl – Header Builder Alternatives
Boostify Header Footer Builder for Elementor
boostify-header-footer-builder
Create Header, Footer and Mega menu for your WordPress website using Elementor Page Builder for free.
Visual Header
visual-header
Visual Header Builder for WordPress
Softtemplates For Elementor
softtemplates-for-elementor
SoftTemplates for Elementor is a plugin that allows you to create a header, footer, blog archive, blog page, search page, single page template and sin …
STAX Header Builder
stax
A header builder that works with any theme. Front-end drag&drop interface to create pixel perfect headers with ease.
Header Builder for Elementor by WPDaddy
wpdaddy-header-builder
WPDaddy header builder was developed for Elementor page builder.
Pearl – Header Builder Developer Profile
8 plugins · 58K total installs
How We Detect Pearl – Header Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pearl-header-builder/frontend/css/header/main.css/wp-content/plugins/pearl-header-builder/frontend/css/sticky.css/wp-content/plugins/pearl-header-builder/frontend/css/font-awesome.min.css/wp-content/plugins/pearl-header-builder/frontend/js/app.js/wp-content/plugins/pearl-header-builder/frontend/js/sticky.js/wp-content/plugins/pearl-header-builder/frontend/js/modal.js/wp-content/plugins/pearl-header-builder/frontend/js/app.js/wp-content/plugins/pearl-header-builder/frontend/js/sticky.js/wp-content/plugins/pearl-header-builder/frontend/js/modal.jspearl-header-builder/frontend/css/header/main.css?ver=pearl-header-builder/frontend/css/sticky.css?ver=pearl-header-builder/frontend/css/font-awesome.min.css?ver=pearl-header-builder/frontend/js/app.js?ver=pearl-header-builder/frontend/js/sticky.js?ver=pearl-header-builder/frontend/js/modal.js?ver=HTML / DOM Fingerprints
stm-header__elementstm-headerstm-header__row_color_topstm-header__row_color_bottomstm-header__row_color_maindata-custom-iddata-header-idSTM_HB_VERSTM_HB_DIRSTM_HB_URLSTM_HB_PATH<div class="stm-header">