
ShelfBuilder Lite Security & Risk Analysis
wordpress.org/plugins/shelfbuilder-liteA visual grid block with drag-and-drop ordering. Hand-pick posts and pages, then arrange them like items on a shelf.
Is ShelfBuilder Lite Safe to Use in 2026?
Generally Safe
Score 100/100ShelfBuilder Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The shelfbuilder-lite plugin v1.0.1 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and 100% proper output escaping are excellent security practices. Furthermore, the lack of recorded vulnerabilities, including critical or high severity ones, and the absence of any critical or high severity taint flows indicate a well-maintained and secure codebase. The plugin also correctly implements capability checks for its REST API routes and has a very limited attack surface consisting solely of REST API endpoints, all of which are protected.
However, a notable concern is the complete absence of nonce checks. While the REST API routes have capability checks, nonces are a crucial layer of defense against Cross-Site Request Forgery (CSRF) attacks, especially for actions that modify data. The lack of any nonce verification on these entry points represents a potential, albeit specific, attack vector. The fact that there are no recorded vulnerabilities to date is positive, but it doesn't entirely negate the risk introduced by the missing nonce checks. A balanced conclusion is that the plugin is robust in its handling of SQL, output, and permissions, but a significant security gap exists with the absence of nonce checks.
Key Concerns
- Missing nonce checks on entry points
ShelfBuilder Lite Security Vulnerabilities
ShelfBuilder Lite Release Timeline
ShelfBuilder Lite Code Analysis
Output Escaping
ShelfBuilder Lite Attack Surface
REST API Routes 3
WordPress Hooks 3
Maintenance & Trust
ShelfBuilder Lite Maintenance & Trust
Maintenance Signals
Community Trust
ShelfBuilder Lite Alternatives
Layout Grid Block
layout-grid
A Gutenberg container block to let you align items consistently across a global grid.
WP Blog Post Layouts
wp-blog-post-layouts
Versatile plugin specially designed to create beautiful posts layouts. Fully compatible with Gutenberg and Elementor. Comes with advanced features suc …
Justified Gallery
justified-gallery
WordPress gallery plugin. Display WordPress galleries in a responsive justified image grid and a pretty lightbox.
Post Layouts for Gutenberg
post-layouts
A beautiful post layouts block to showcase your posts in grid and list layout with multiple templates availability.
AinoBlocks – Gutenberg Website Builder Blocks
aino-blocks
A collection of blocks for the Gutenberg block editor to build professional WordPress websites.
ShelfBuilder Lite Developer Profile
1 plugin · 0 total installs
How We Detect ShelfBuilder Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shelfbuilder-lite/assets/js/editor.js/wp-content/plugins/shelfbuilder-lite/assets/css/editor.css/wp-content/plugins/shelfbuilder-lite/assets/css/frontend.css/wp-content/plugins/shelfbuilder-lite/assets/js/editor.jsshelfbuilder-lite/assets/js/editor.js?ver=shelfbuilder-lite/assets/css/editor.css?ver=shelfbuilder-lite/assets/css/frontend.css?ver=HTML / DOM Fingerprints
/wp-json/shelfbuilder-lite/v1/items/wp-json/shelfbuilder-lite/v1/source-types/wp-json/shelfbuilder-lite/v1/filter-taxonomies