
Lewe Bootstrap Visuals Security & Risk Analysis
wordpress.org/plugins/shortcode-bootstrap-visualsA WordPress plugin that provides Bootstrap visual components through easy-to-use shortcodes.
Is Lewe Bootstrap Visuals Safe to Use in 2026?
Mostly Safe
Score 79/100Lewe Bootstrap Visuals is generally safe to use. 1 past CVE were resolved.
The shortcode-bootstrap-visuals plugin version 3.0.1 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, all SQL queries utilize prepared statements, output is properly escaped, and there are no file operations or external HTTP requests. Furthermore, there are no known critical or high-severity vulnerabilities discovered through taint analysis, and the total entry points are not directly exposed without authentication or capability checks.
However, significant concerns arise from the vulnerability history. The plugin has a known medium-severity Cross-Site Scripting (XSS) vulnerability that remains unpatched. The presence of a recent XSS vulnerability, even if medium-severity, indicates a potential for malicious actors to inject and execute arbitrary scripts, which can lead to session hijacking, defacement, or other harmful actions. The lack of nonce checks on the entry points (shortcodes), combined with the history of XSS, suggests that while the current static analysis might not immediately flag a flaw, the plugin's architecture could be susceptible to certain types of attacks if user-supplied data is not handled with extreme care within the shortcode's execution context.
In conclusion, while the plugin demonstrates good practices in areas like prepared statements and output escaping, the unpatched XSS vulnerability is a critical concern that overshadows these strengths. The absence of nonce checks on shortcodes, coupled with the history of input sanitization issues, warrants careful consideration. Users should prioritize updating the plugin if a patch becomes available or explore alternative solutions if this vulnerability cannot be mitigated.
Key Concerns
- Unpatched medium severity CVE
- No nonce checks on shortcodes
Lewe Bootstrap Visuals Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Lewe Bootstrap Visuals <= 2.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Lewe Bootstrap Visuals Release Timeline
Lewe Bootstrap Visuals Code Analysis
Bundled Libraries
Output Escaping
Lewe Bootstrap Visuals Attack Surface
Shortcodes 11
WordPress Hooks 2
Maintenance & Trust
Lewe Bootstrap Visuals Maintenance & Trust
Maintenance Signals
Community Trust
Lewe Bootstrap Visuals Alternatives
No alternatives data available yet.
Lewe Bootstrap Visuals Developer Profile
3 plugins · 220 total installs
How We Detect Lewe Bootstrap Visuals
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-alert.css/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-badge.css/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-button.css/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-card.css/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-carousel.css/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-forms.css/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-image.css/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-modal.css+11 more/wp-content/plugins/shortcode-bootstrap-visuals/assets/js/bsv-alert.js/wp-content/plugins/shortcode-bootstrap-visuals/assets/js/bsv-carousel.js/wp-content/plugins/shortcode-bootstrap-visuals/assets/js/bsv-modal.js/wp-content/plugins/shortcode-bootstrap-visuals/assets/js/bsv-tabs.js/wp-content/plugins/shortcode-bootstrap-visuals/assets/js/bsv-tooltip.js/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-alert.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-badge.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-button.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-card.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-carousel.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-forms.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-image.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-modal.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-navigation.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-pagination.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-progress.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-table.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-tabs.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-tooltip.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/js/bsv-alert.js?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/js/bsv-carousel.js?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/js/bsv-modal.js?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/js/bsv-tabs.js?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/js/bsv-tooltip.js?ver=HTML / DOM Fingerprints
bsv-alertbsv-badgebsv-blockquotebsv-buttonbsv-cardbsv-carouselbsv-collapsebsv-dropdown+11 more<!-- Shortcode Bootstrap Visuals: BSW Alert Start --><!-- Shortcode Bootstrap Visuals: BSW Alert End --><!-- Shortcode Bootstrap Visuals: BSW Badge Start --><!-- Shortcode Bootstrap Visuals: BSW Badge End -->+32 moredata-bsv-dismissibledata-bsv-target-iddata-bsv-carousel-intervaldata-bsv-modal-target-iddata-bsv-tab-iddata-bsv-tooltip-idbsv_alert_instancesbsv_carousel_instancesbsv_modal_instancesbsv_tabs_instancesbsv_tooltip_instances<div class="bsv-alert<span class="bsv-badge<blockquote class="bsv-blockquote<a class="bsv-btn