
SP Blog Designer Security & Risk Analysis
wordpress.org/plugins/sp-blog-designerUsing this plugin you can design your blog pages in few clicks and it's very easy to use. There is so many options to match your theme with creat …
Is SP Blog Designer Safe to Use in 2026?
High Risk
Score 41/100SP Blog Designer carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The "sp-blog-designer" plugin v1.0.0 presents a significant security risk due to a combination of insecure coding practices and a history of critical vulnerabilities. While the plugin demonstrates good practice by utilizing prepared statements for all SQL queries, this is overshadowed by fundamental security flaws. A notable concern is the presence of 2 AJAX handlers without authentication checks, creating a direct attack vector. Furthermore, the taint analysis reveals 3 flows analyzed, with 1 of high severity and all 3 involving unsanitized paths, indicating potential for serious exploits. The plugin's vulnerability history, with 2 known CVEs that remain unpatched, including a high-severity vulnerability and a medium-severity one, directly points to recurring security weaknesses. The common vulnerability types of Missing Authorization and PHP Remote File Inclusion are particularly alarming as they can lead to complete site compromise. The plugin's latest vulnerability was recently discovered, suggesting ongoing issues.
While the plugin does not appear to use dangerous functions or perform risky file operations, and has a moderate number of total outputs with a concerningly low percentage properly escaped, the lack of nonces and capability checks on its entry points, especially the unprotected AJAX handlers, combined with the untainted flows and historical vulnerabilities, paint a grim picture. The external HTTP request also introduces a potential avenue for further compromise if the external endpoint is malicious or compromised. The low percentage of properly escaped output is a concern for Cross-Site Scripting (XSS) vulnerabilities, though not explicitly highlighted as a taint flow issue. Overall, this plugin should be considered highly risky and likely requires immediate attention or removal until these critical security deficiencies are addressed.
Key Concerns
- Unpatched High Severity CVE
- Unpatched Medium Severity CVE
- High Severity Taint Flow
- Unsanitized Paths in Taint Flows (3)
- AJAX Handlers without Auth Checks (2)
- Missing Nonce Checks on Entry Points
- Missing Capability Checks on Entry Points
- Low Output Escaping Percentage (13%)
- External HTTP Request
SP Blog Designer Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
SP Blog Designer <= 1.0.0 - Unauthenticated Arbitrary Shortcode Execution
SP Blog Designer <= 1.0.0 - Authenticated (Contributor+) Local File Inclusion
SP Blog Designer Code Analysis
Output Escaping
Data Flow Analysis
SP Blog Designer Attack Surface
AJAX Handlers 2
Shortcodes 3
WordPress Hooks 7
Maintenance & Trust
SP Blog Designer Maintenance & Trust
Maintenance Signals
Community Trust
SP Blog Designer Alternatives
Blogsqode – Blog Layouts and News Post Design
blogsqode-posts
Blogsqode is an effective and user-friendly way to beautify your blog pages on your websites.
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging
wp-rss-aggregator
The #1 WordPress RSS aggregator to quickly import RSS feeds, build a news aggregator, and for easy autoblogging.
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator
feedzy-rss-feeds
The most powerful WordPress RSS aggregator, helping you curate content, autoblog, import RSS & display unlimited RSS feeds within a few minutes.
Blog Designer Pack – Blog, Post Grid, Post Slider, Post Carousel, Category Post, News
blog-designer-pack
News & Blog plugin for post grid, post slider, post carousel, post filter, masonry, ticker & list category posts using shortcode, Elementor & Divi.
BlockSpare — News, Magazine and Blog Addons for (Gutenberg) Block Editor
blockspare
Highly customizable Gutenberg blocks and starter templates to build blogs, magazines, and business websites. Create post grids, sliders, filters, and …
SP Blog Designer Developer Profile
3 plugins · 230 total installs
How We Detect SP Blog Designer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sp-blog-designer/assets/css/sp-admin.css/wp-content/plugins/sp-blog-designer/assets/css/sp-blogs.css/wp-content/plugins/sp-blog-designer/assets/css/slick.css/wp-content/plugins/sp-blog-designer/assets/js/sp-frontend.min.js/wp-content/plugins/sp-blog-designer/assets/js/slick.min.js/wp-content/plugins/sp-blog-designer/assets/js/sp-shortcode.min.js/wp-content/plugins/sp-blog-designer/assets/js/sp-color-picker.jshttps://fonts.googleapis.com/css2?family=Libre+Franklin:wght@400;600;700&display=swapsp-blog-designer/assets/css/sp-admin.css?ver=sp-blog-designer/assets/css/sp-blogs.css?ver=sp-blog-designer/assets/css/slick.css?ver=sp-blog-designer/assets/js/sp-frontend.min.js?ver=sp-blog-designer/assets/js/slick.min.js?ver=sp-blog-designer/assets/js/sp-shortcode.min.js?ver=sp-blog-designer/assets/js/sp-color-picker.js?ver=HTML / DOM Fingerprints
sp-blog-designersp-blog-designersp_Short_GeneratorParam/wp-json/spbd/v1/preview[wpsbd_post][wpsbd_post_list][wpsbd_post_carousel]