Lewe Bootstrap Visuals Security & Risk Analysis

wordpress.org/plugins/shortcode-bootstrap-visuals

A WordPress plugin that provides Bootstrap visual components through easy-to-use shortcodes.

10 active installs v3.0.1 PHP 7.4+ WP 5.0+ Updated Mar 27, 2026
lewe-bootstrap-shortcode-styles-visual
79
B · Generally Safe
CVEs total1
Unpatched1
Last CVENov 8, 2024
Safety Verdict

Is Lewe Bootstrap Visuals Safe to Use in 2026?

Mostly Safe

Score 79/100

Lewe Bootstrap Visuals is generally safe to use. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Nov 8, 2024Updated 1mo ago
Risk Assessment

The shortcode-bootstrap-visuals plugin version 3.0.1 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, all SQL queries utilize prepared statements, output is properly escaped, and there are no file operations or external HTTP requests. Furthermore, there are no known critical or high-severity vulnerabilities discovered through taint analysis, and the total entry points are not directly exposed without authentication or capability checks.

However, significant concerns arise from the vulnerability history. The plugin has a known medium-severity Cross-Site Scripting (XSS) vulnerability that remains unpatched. The presence of a recent XSS vulnerability, even if medium-severity, indicates a potential for malicious actors to inject and execute arbitrary scripts, which can lead to session hijacking, defacement, or other harmful actions. The lack of nonce checks on the entry points (shortcodes), combined with the history of XSS, suggests that while the current static analysis might not immediately flag a flaw, the plugin's architecture could be susceptible to certain types of attacks if user-supplied data is not handled with extreme care within the shortcode's execution context.

In conclusion, while the plugin demonstrates good practices in areas like prepared statements and output escaping, the unpatched XSS vulnerability is a critical concern that overshadows these strengths. The absence of nonce checks on shortcodes, coupled with the history of input sanitization issues, warrants careful consideration. Users should prioritize updating the plugin if a patch becomes available or explore alternative solutions if this vulnerability cannot be mitigated.

Key Concerns

  • Unpatched medium severity CVE
  • No nonce checks on shortcodes
Vulnerabilities
1 published

Lewe Bootstrap Visuals Security Vulnerabilities

CVEs by Year

1 CVE in 2024 · unpatched
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-51810medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Lewe Bootstrap Visuals <= 2.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 8, 2024Unpatched
Version History

Lewe Bootstrap Visuals Release Timeline

v3.0.1Current1 CVE
v3.0.01 CVE
v2.2.21 CVE
v2.2.11 CVE
v2.2.01 CVE
v2.1.11 CVE
v2.1.01 CVE
v2.0.21 CVE
v2.0.11 CVE
v2.0.01 CVE
v1.5.01 CVE
v1.4.01 CVE
v1.3.21 CVE
v1.3.11 CVE
v1.3.01 CVE
Code Analysis
Analyzed Apr 16, 2026

Lewe Bootstrap Visuals Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

100% escaped2 total outputs
Attack Surface

Lewe Bootstrap Visuals Attack Surface

Entry Points11
Unprotected0

Shortcodes 11

[bsv-alert] inc/shortcodes.php:54
[bsv-badge] inc/shortcodes.php:106
[bsv-blockquote] inc/shortcodes.php:142
[bsv-button] inc/shortcodes.php:189
[bsv-button-group] inc/shortcodes.php:222
[bsv-callout] inc/shortcodes.php:259
[bsv-card] inc/shortcodes.php:314
[bsv-jumbo] inc/shortcodes.php:351
[bsv-panel] inc/shortcodes.php:403
[bsv-progress] inc/shortcodes.php:444
[bsv-spinner] inc/shortcodes.php:484
WordPress Hooks 2
actionadmin_noticesshortcode-bootstrap-visuals.php:35
actionplugins_loadedshortcode-bootstrap-visuals.php:80
Maintenance & Trust

Lewe Bootstrap Visuals Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 27, 2026
PHP min version7.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Lewe Bootstrap Visuals Alternatives

No alternatives data available yet.

Developer Profile

Lewe Bootstrap Visuals Developer Profile

George Lewe

3 plugins · 220 total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Lewe Bootstrap Visuals

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-alert.css/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-badge.css/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-button.css/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-card.css/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-carousel.css/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-forms.css/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-image.css/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-modal.css+11 more
Script Paths
/wp-content/plugins/shortcode-bootstrap-visuals/assets/js/bsv-alert.js/wp-content/plugins/shortcode-bootstrap-visuals/assets/js/bsv-carousel.js/wp-content/plugins/shortcode-bootstrap-visuals/assets/js/bsv-modal.js/wp-content/plugins/shortcode-bootstrap-visuals/assets/js/bsv-tabs.js/wp-content/plugins/shortcode-bootstrap-visuals/assets/js/bsv-tooltip.js
Version Parameters
/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-alert.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-badge.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-button.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-card.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-carousel.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-forms.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-image.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-modal.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-navigation.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-pagination.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-progress.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-table.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-tabs.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/css/bsv-tooltip.css?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/js/bsv-alert.js?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/js/bsv-carousel.js?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/js/bsv-modal.js?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/js/bsv-tabs.js?ver=/wp-content/plugins/shortcode-bootstrap-visuals/assets/js/bsv-tooltip.js?ver=

HTML / DOM Fingerprints

CSS Classes
bsv-alertbsv-badgebsv-blockquotebsv-buttonbsv-cardbsv-carouselbsv-collapsebsv-dropdown+11 more
HTML Comments
<!-- Shortcode Bootstrap Visuals: BSW Alert Start --><!-- Shortcode Bootstrap Visuals: BSW Alert End --><!-- Shortcode Bootstrap Visuals: BSW Badge Start --><!-- Shortcode Bootstrap Visuals: BSW Badge End -->+32 more
Data Attributes
data-bsv-dismissibledata-bsv-target-iddata-bsv-carousel-intervaldata-bsv-modal-target-iddata-bsv-tab-iddata-bsv-tooltip-id
JS Globals
bsv_alert_instancesbsv_carousel_instancesbsv_modal_instancesbsv_tabs_instancesbsv_tooltip_instances
Shortcode Output
<div class="bsv-alert<span class="bsv-badge<blockquote class="bsv-blockquote<a class="bsv-btn
FAQ

Frequently Asked Questions about Lewe Bootstrap Visuals