
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Security & Risk Analysis
wordpress.org/plugins/post-and-page-builderPost and Page Builder is a standalone plugin which adds functionality to the existing TinyMCE Editor.
Is Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Safe to Use in 2026?
Generally Safe
Score 95/100Post and Page Builder by BoldGrid – Visual Drag and Drop Editor has a strong security track record. Known vulnerabilities have been patched promptly.
The "post-and-page-builder" plugin v1.27.10 presents a mixed security posture. While the plugin demonstrates good practices in handling SQL queries and includes a reasonable number of nonce and capability checks, significant concerns arise from its large attack surface exposed through AJAX handlers without authentication. The presence of 11 unprotected AJAX entry points is a critical weakness, as it allows unauthenticated users to potentially interact with sensitive plugin functionalities.
The taint analysis, although showing no critical or high severity unsanitized flows, did identify 3 flows with unsanitized paths. Combined with the vulnerability history, which shows a concerning pattern of past vulnerabilities including Missing Authorization, CSRF, SSRF, Path Traversal, and XSS, these findings suggest a recurring need for diligent input validation and authorization checks. The plugin's history of 10 medium severity CVEs, even though none are currently unpatched, indicates a historical tendency for exploitable flaws, requiring ongoing vigilance.
In conclusion, the plugin has strengths in its database interaction and some security control implementations. However, the high number of unprotected AJAX endpoints is a major risk. The historical vulnerability patterns reinforce the need for developers to prioritize robust input sanitization and strict access control across all entry points to mitigate potential exploits.
Key Concerns
- 11 unprotected AJAX handlers
- 3 flows with unsanitized paths
- 47% output escaping
- 10 medium severity CVEs in history
- Common vulnerability types: Missing Auth, CSRF, SSRF, Path Traversal, XSS
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Security Vulnerabilities
CVEs by Year
Severity Breakdown
10 total CVEs
Post and Page Builder by BoldGrid <= 1.27.9 - Missing Authorization
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.27.8 - Authenticated (Contributor+) Path Traversal
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.27.8 - Cross-Site Request Forgery
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.27.8 - Authenticated (Contributor+) Server-Side Request Forgery
Post and Page Builder by BoldGrid <= 1.27.6 - Path Traversal to Authenticated (Contributor+) Arbitrary File Read via template_via_url Function
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.27.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via File Upload
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.4 - Authenticated (Contributer+) Stored Cross-Site Scripting
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Plugin <= 1.26.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.24.1 - Cross-Site Request Forgery via submitDefaultEditor
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Attack Surface
AJAX Handlers 11
Shortcodes 1
WordPress Hooks 95
Maintenance & Trust
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Maintenance & Trust
Maintenance Signals
Community Trust
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Alternatives
Elementor Website Builder – More Than Just a Page Builder
elementor
The Elementor Website Builder has it all: drag and drop page builder, pixel perfect design, mobile responsive editing, and more. Get started now!
Page Builder by SiteOrigin
siteorigin-panels
Build responsive page layouts using the widgets you know and love using this simple drag and drop page builder.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Beaver Builder Page Builder – Drag and Drop Website Builder
beaver-builder-lite-version
The Professional's Choice for Drag & Drop WordPress Page Building. Fast, Reliable, and Trusted since 2014.
Colibri Page Builder
colibri-page-builder
Colibri Page Builder adds drag and drop page builder functionality to the ColibriWP theme.
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Developer Profile
15 plugins · 1.1M total installs
How We Detect Post and Page Builder by BoldGrid – Visual Drag and Drop Editor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-and-page-builder/dist/js/boldgrid-editor-frontend.js/wp-content/plugins/post-and-page-builder/dist/css/boldgrid-editor-frontend.css/wp-content/plugins/post-and-page-builder/dist/js/boldgrid-editor-backend.js/wp-content/plugins/post-and-page-builder/dist/css/boldgrid-editor-backend.css/wp-content/plugins/post-and-page-builder/vendor/autoload.phppost-and-page-builder/dist/js/boldgrid-editor-frontend.js?ver=post-and-page-builder/dist/css/boldgrid-editor-frontend.css?ver=post-and-page-builder/dist/js/boldgrid-editor-backend.js?ver=post-and-page-builder/dist/css/boldgrid-editor-backend.css?ver=HTML / DOM Fingerprints
boldgrid-editor-wrapperbg-font-family-altbg-font-family-bodybg-font-family-headingbg-font-family-menu<!-- BoldGrid Editor Content --><!-- Content --><!-- Page and Post Builder Content --><!-- End Page and Post Builder Content -->+4 moredata-boldgrid-editorwindow.BoldgridEditor