
Query Forge Security & Risk Analysis
wordpress.org/plugins/query-forgeVisual node-based query builder for WordPress. Works with the block editor and Elementor. Build complex post queries with a drag-and-drop interface — …
Is Query Forge Safe to Use in 2026?
Generally Safe
Score 100/100Query Forge has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "query-forge" v1.3.4 plugin exhibits a generally strong security posture, largely due to its adherence to secure coding practices. The absence of known CVEs and the plugin's consistent use of prepared statements for all SQL queries are significant strengths. Furthermore, the comprehensive use of nonce and capability checks across its 10 AJAX entry points, coupled with a very high percentage of properly escaped output, demonstrates a conscious effort to prevent common web vulnerabilities. The plugin also avoids dangerous functions, file operations, and external HTTP requests, further reducing its attack surface.
However, the static analysis did reveal three flows with unsanitized paths. While the taint analysis did not classify these as critical or high severity, unsanitized paths represent a potential risk. If these paths are exposed to user input without proper sanitization or validation, they could lead to unexpected behavior or, in a worst-case scenario, more severe vulnerabilities. The absence of REST API routes and shortcodes, while reducing the overall attack surface, means the security focus is primarily on AJAX handlers.
In conclusion, "query-forge" v1.3.4 is a well-developed plugin from a security perspective, with excellent implementation of fundamental security controls. The main area for improvement lies in addressing the identified unsanitized paths to ensure the complete elimination of potential security weaknesses. The plugin's clean vulnerability history reinforces its current secure state, but proactive mitigation of the identified taint flow issues is recommended for optimal security.
Key Concerns
- Flows with unsanitized paths
Query Forge Security Vulnerabilities
Query Forge Release Timeline
Query Forge Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Query Forge Attack Surface
AJAX Handlers 12
WordPress Hooks 15
Maintenance & Trust
Query Forge Maintenance & Trust
Maintenance Signals
Community Trust
Query Forge Alternatives
Content Views – Post Grid & Filter, Recent Posts, Category Posts … (Shortcode, Gutenberg Blocks, and Widgets for Elementor)
content-views-query-and-display-post-page
Easy to show posts, pages, custom posts in customizable grid, list, slider, accordion... Available as Widgets (for Elementor), Shortcode, and Blocks.
Starter Templates – AI-Powered Templates for Elementor & Gutenberg
astra-sites
The growing library of 300+ ready-to-use templates that work with all WordPress themes including Astra, Hello, OceanWP, GeneratePress and more
GenerateBlocks
generateblocks
A small collection of lightweight WordPress blocks that can accomplish nearly anything.
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
woolentor-addons
ShopLentor – More than a WooCommerce builder. A complete growth plugin to boost conversions, UX, and sales for your store.
UiCore Animate – Free Animations, Transitions, and Interactions Addon for Elementor & Gutenberg blocks
uicore-animate
UiCore Animate adds page transitions, smooth scroll, and engaging animations to Elementor and Gutenberg blocks, for smoother, engaging experiences.
Query Forge Developer Profile
1 plugin · 0 total installs
How We Detect Query Forge
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/query-forge/assets/css/qf-widget.css/wp-content/plugins/query-forge/assets/js/qf-widget.js/wp-content/plugins/query-forge/assets/js/qf-widget.jsquery-forge/assets/css/qf-widget.css?ver=query-forge/assets/js/qf-widget.js?ver=HTML / DOM Fingerprints
qf-query-forge-rootqf-search-wrapperqf-search-fieldqf-search-buttonqf-results-containerqf-result-itemqf-paginationdata-qf-instance-iddata-qf-posts-per-pagedata-qf-current-pagedata-qf-search-activedata-qf-search-enableddata-qf-search-field+3 moreQueryForgeWidget/wp-json/query-forge/v1/search/wp-json/query-forge/v1/suggestions