ShelfBuilder Lite Security & Risk Analysis

wordpress.org/plugins/shelfbuilder-lite

A visual grid block with drag-and-drop ordering. Hand-pick posts and pages, then arrange them like items on a shelf.

0 active installs v1.0.1 PHP 7.4+ WP 6.0+ Updated Mar 22, 2026
blockdrag-dropgallerygridlayout
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ShelfBuilder Lite Safe to Use in 2026?

Generally Safe

Score 100/100

ShelfBuilder Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The shelfbuilder-lite plugin v1.0.1 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and 100% proper output escaping are excellent security practices. Furthermore, the lack of recorded vulnerabilities, including critical or high severity ones, and the absence of any critical or high severity taint flows indicate a well-maintained and secure codebase. The plugin also correctly implements capability checks for its REST API routes and has a very limited attack surface consisting solely of REST API endpoints, all of which are protected.

However, a notable concern is the complete absence of nonce checks. While the REST API routes have capability checks, nonces are a crucial layer of defense against Cross-Site Request Forgery (CSRF) attacks, especially for actions that modify data. The lack of any nonce verification on these entry points represents a potential, albeit specific, attack vector. The fact that there are no recorded vulnerabilities to date is positive, but it doesn't entirely negate the risk introduced by the missing nonce checks. A balanced conclusion is that the plugin is robust in its handling of SQL, output, and permissions, but a significant security gap exists with the absence of nonce checks.

Key Concerns

  • Missing nonce checks on entry points
Vulnerabilities
None known

ShelfBuilder Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

ShelfBuilder Lite Release Timeline

v1.0.1Current
Code Analysis
Analyzed Apr 16, 2026

ShelfBuilder Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
27 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped27 total outputs
Attack Surface

ShelfBuilder Lite Attack Surface

Entry Points3
Unprotected0

REST API Routes 3

GET/wp-json/shelfbuilder-lite/v1/itemsshelfbuilder-lite.php:126
GET/wp-json/shelfbuilder-lite/v1/source-typesshelfbuilder-lite.php:151
GET/wp-json/shelfbuilder-lite/v1/filter-taxonomiesshelfbuilder-lite.php:159
WordPress Hooks 3
actionadmin_noticesshelfbuilder-lite.php:42
actioninitshelfbuilder-lite.php:120
actionrest_api_initshelfbuilder-lite.php:174
Maintenance & Trust

ShelfBuilder Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 22, 2026
PHP min version7.4
Downloads165

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ShelfBuilder Lite Developer Profile

jkolodziej

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ShelfBuilder Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shelfbuilder-lite/assets/js/editor.js/wp-content/plugins/shelfbuilder-lite/assets/css/editor.css/wp-content/plugins/shelfbuilder-lite/assets/css/frontend.css
Script Paths
/wp-content/plugins/shelfbuilder-lite/assets/js/editor.js
Version Parameters
shelfbuilder-lite/assets/js/editor.js?ver=shelfbuilder-lite/assets/css/editor.css?ver=shelfbuilder-lite/assets/css/frontend.css?ver=

HTML / DOM Fingerprints

REST Endpoints
/wp-json/shelfbuilder-lite/v1/items/wp-json/shelfbuilder-lite/v1/source-types/wp-json/shelfbuilder-lite/v1/filter-taxonomies
FAQ

Frequently Asked Questions about ShelfBuilder Lite