Pollen – WPBakery Page Builder Addons Security & Risk Analysis

wordpress.org/plugins/pollen

Pollen - WPBakery Page Builder Addons allows you to create amazing pages from ready to use templates with a single click only.

200 active installs v1.0.8 PHP 5.4+ WP 4.7+ Updated Mar 8, 2021
drag-and-dropeditorlanding-pagepage-buildervisual-composer
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pollen – WPBakery Page Builder Addons Safe to Use in 2026?

Generally Safe

Score 85/100

Pollen – WPBakery Page Builder Addons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The Pollen plugin v1.0.8 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for all SQL queries and does not appear to have any known historical vulnerabilities. This suggests a developer who is aware of common SQL injection pitfalls and committed to security patching. However, there are notable concerns that warrant attention. The plugin has a relatively high number of entry points (7), with one AJAX handler lacking authentication checks. This directly exposes a potential attack vector. Additionally, a significant portion (48%) of its output escaping is not properly handled, indicating a risk of cross-site scripting (XSS) vulnerabilities if user-controlled data is displayed without adequate sanitization. The presence of unsanitized paths in taint analysis, even without critical severity, should be investigated further as it can lead to path traversal or other file-related vulnerabilities.

While the lack of critical or high-severity findings in the static analysis and vulnerability history is encouraging, the identified weaknesses are not negligible. The unprotected AJAX handler is a direct and exploitable vulnerability. The high percentage of unescaped output suggests a systemic issue with output sanitization that could lead to multiple XSS vulnerabilities. The presence of unsanitized paths in taint analysis, though not flagged as critical, still represents a potential weakness. The plugin's strengths lie in its secure SQL handling and absence of historical CVEs. However, the current implementation has clear vulnerabilities related to authentication and output escaping that must be addressed to improve its overall security.

Key Concerns

  • AJAX handler without auth check
  • High percentage of unescaped output (52%)
  • Flows with unsanitized paths (4)
Vulnerabilities
None known

Pollen – WPBakery Page Builder Addons Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Pollen – WPBakery Page Builder Addons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
413
444 escaped
Nonce Checks
5
Capability Checks
1
File Operations
26
External Requests
15
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

52% escaped857 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

7 flows4 with unsanitized paths
save_network_page (includes\options\core\framework.php:591)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Pollen – WPBakery Page Builder Addons Attack Surface

Entry Points7
Unprotected1

AJAX Handlers 7

noprivwp_ajax_redux_pincludes\options\core\inc\class.p.php:7
authwp_ajax_redux_pincludes\options\core\inc\class.p.php:8
authwp_ajax_redux_hide_admin_noticeincludes\options\core\inc\class.redux_admin_notices.php:32
authwp_ajax_redux_allow_trackingincludes\options\core\inc\tracking.php:510
authwp_ajax_redux_support_hashincludes\options\core\inc\welcome\welcome.php:25
authwp_ajax_pollen_ajax_add_zipped_fontincludes\paramns\icon-manager\icon-manager.php:25
authwp_ajax_pollen_ajax_remove_zipped_fontincludes\paramns\icon-manager\icon-manager.php:26
WordPress Hooks 63
actionvc_after_initincludes\elements\custom-default-elements.php:13
actionwp_dashboard_setupincludes\options\core\core\dashboard.php:13
actionredux/initincludes\options\core\framework.php:30
actionadmin_menuincludes\options\core\framework.php:351
actionnetwork_admin_menuincludes\options\core\framework.php:355
actionadmin_bar_menuincludes\options\core\framework.php:359
actionadmin_initincludes\options\core\framework.php:365
actionadmin_initincludes\options\core\framework.php:370
actionadmin_noticesincludes\options\core\framework.php:375
actionadmin_initincludes\options\core\framework.php:378
actionadmin_enqueue_scriptsincludes\options\core\framework.php:382
actionwp_headincludes\options\core\framework.php:388
actionwp_enqueue_scriptsincludes\options\core\framework.php:389
actionlogin_headincludes\options\core\framework.php:394
actionlogin_enqueue_scriptsincludes\options\core\framework.php:395
actionadmin_headincludes\options\core\framework.php:400
actionadmin_enqueue_scriptsincludes\options\core\framework.php:401
actionwp_print_scriptsincludes\options\core\framework.php:405
actionadmin_enqueue_scriptsincludes\options\core\framework.php:406
actionadmin_bar_menuincludes\options\core\framework.php:414
actionadmin_headincludes\options\core\framework.php:1712
filteradmin_footer_textincludes\options\core\framework.php:1715
actionafter_setup_themeincludes\options\core\inc\class.redux_api.php:47
actioninitincludes\options\core\inc\class.redux_api.php:48
actionswitch_themeincludes\options\core\inc\class.redux_api.php:49
actionredux/constructincludes\options\core\inc\class.redux_instances.php:66
actioncustomize_registerincludes\options\core\inc\extensions\customizer\extension_customizer.php:113
actionwp_headincludes\options\core\inc\extensions\customizer\extension_customizer.php:118
actioncustomize_save_afterincludes\options\core\inc\extensions\customizer\extension_customizer.php:122
actioncustomize_controls_print_scriptsincludes\options\core\inc\extensions\customizer\extension_customizer.php:125
actioncustomize_controls_initincludes\options\core\inc\extensions\customizer\extension_customizer.php:127
filterupload_mimesincludes\options\core\inc\extensions\import_export\extension_import_export.php:97
filterredux/font-iconsincludes\options\core\inc\fields\select\elusive-icons.php:312
actionadmin_enqueue_scriptsincludes\options\core\inc\themecheck\class.redux_themecheck.php:74
actionadmin_enqueue_scriptsincludes\options\core\inc\themecheck\class.redux_themecheck.php:75
actionthemecheck_checks_loadedincludes\options\core\inc\themecheck\class.redux_themecheck.php:77
actionthemecheck_checks_loadedincludes\options\core\inc\themecheck\class.redux_themecheck.php:78
actionadmin_enqueue_scriptsincludes\options\core\inc\tracking.php:81
actionadmin_enqueue_scriptsincludes\options\core\inc\tracking.php:83
actionredux_trackingincludes\options\core\inc\tracking.php:100
actionadmin_print_footer_scriptsincludes\options\core\inc\tracking.php:110
actionadmin_print_footer_scriptsincludes\options\core\inc\tracking.php:119
filterredux/tracking/optionsincludes\options\core\inc\tracking.php:486
actioninitincludes\options\core\inc\validation\unique_slug\validation_unique_slug.php:60
actionredux/loadedincludes\options\core\inc\welcome\welcome.php:23
actionadmin_menuincludes\options\core\inc\welcome\welcome.php:35
filteradmin_footer_textincludes\options\core\inc\welcome\welcome.php:41
actionadmin_headincludes\options\core\inc\welcome\welcome.php:42
actioninitincludes\options\core\inc\welcome\welcome.php:91
actionadmin_menuincludes\paramns\icon-manager\icon-manager.php:574
actionwp_enqueue_scriptsincludes\paramns\icon-manager\icon-manager.php:610
filterupload_mimesincludes\svg\svg.php:32
filterwp_check_filetype_and_extincludes\svg\svg.php:47
filterwp_handle_upload_prefilterincludes\svg\svg.php:72
filterimage_downsizeincludes\svg\svg.php:85
filterwp_prepare_attachment_for_jsincludes\svg\svg.php:129
actionwp_enqueue_scriptsincludes\svg\svg.php:138
actionadmin_menupollen.php:33
actionadmin_menupollen.php:43
actioninitpollen.php:71
actionadmin_enqueue_scriptspollen.php:76
actionwp_enqueue_scriptspollen.php:79
actionadmin_noticespollen.php:115

Scheduled Events 1

redux_tracking
Maintenance & Trust

Pollen – WPBakery Page Builder Addons Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedMar 8, 2021
PHP min version5.4
Downloads10K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

Pollen – WPBakery Page Builder Addons Developer Profile

Visualmodo

3 plugins · 5K total installs

80
trust score
Avg Security Score
88/100
Avg Patch Time
46 days
View full developer profile
Detection Fingerprints

How We Detect Pollen – WPBakery Page Builder Addons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pollen/assets/css/backend.css/wp-content/plugins/pollen/assets/css/pollen.min.css/wp-content/plugins/pollen/assets/js/pollen.js
Script Paths
/wp-content/plugins/pollen/assets/js/pollen.js
Version Parameters
pollen/style.css?ver=pollen_frontend_stylepollen_frontend_script

HTML / DOM Fingerprints

CSS Classes
pollen-page-welcomepollen-page-logopollen-page-actionspollen-button-settingspollen-alertpollen-alert-successpollen-alert-infopollen-alert-warning+5 more
Data Attributes
pollen-alert-close-button
Shortcode Output
<div class="pollen-alert<span class="pollen-alert-close-button"
FAQ

Frequently Asked Questions about Pollen – WPBakery Page Builder Addons