
Space Boxes Security & Risk Analysis
wordpress.org/plugins/space-boxesGenerate unlimited boxes with multiple layouts and optional lightbox, solely from a Wordpress media gallery.
Is Space Boxes Safe to Use in 2026?
Generally Safe
Score 85/100Space Boxes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "space-boxes" plugin version 1.1.1 presents a mixed security posture. On the positive side, it boasts a limited attack surface with no exposed AJAX handlers or REST API routes without authentication. The absence of known historical vulnerabilities (CVEs) and the consistent use of prepared statements for SQL queries are strong indicators of good development practices in these areas. Furthermore, the lack of file operations and external HTTP requests reduces potential attack vectors. However, significant concerns arise from the static analysis. The presence of the `create_function` dangerous function is a notable red flag, as it can be a vector for code injection if not handled with extreme care. Additionally, a substantial portion of output (76%) is not properly escaped, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the presence of shortcodes which are often used to display user-generated or dynamically generated content. The complete absence of nonce checks and capability checks on the identified entry points further exacerbates the XSS risk, allowing unauthenticated users to potentially trigger script execution.
Key Concerns
- Dangerous function usage (create_function)
- Insufficient output escaping (24% properly escaped)
- Missing nonce checks on entry points
- Missing capability checks on entry points
Space Boxes Security Vulnerabilities
Space Boxes Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Space Boxes Attack Surface
Shortcodes 2
WordPress Hooks 14
Maintenance & Trust
Space Boxes Maintenance & Trust
Maintenance Signals
Community Trust
Space Boxes Alternatives
Elements For Elementor
nd-elements
The plugin adds some useful elements to the Elementor Page Builder Plugin. All components are full responsive and retina ready.
Bootstrap Shortcodes
bootstrap-shortcodes
Wordpress plugin to add shortcodes for Twitter Bootstrap 3.3
Grid Shortcodes
grid-shortcodes
A responsive and easy-to-use tool for dividing your content in your posts/pages. This ultra-lightweight plugin allows you to put your content in colum …
Font Awesome Box Shortcode
fa-box-shortcode
The Font Awesome box shortcode plugin adds slim information box style shortcodes to your WordPress site which support displaying any of the Font Aweso …
TW Shortcodes
tw-shortcodes
TW Shortcodes enables you to easily add "flat design" buttons, icons, pricing tables and more without modifying CSS, HTML or PHP.
Space Boxes Developer Profile
4 plugins · 280 total installs
How We Detect Space Boxes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/space-boxes/inc/css/spacebox-admin.css/wp-content/plugins/space-boxes/inc/css/spacebox-frontend.css/wp-content/plugins/space-boxes/inc/js/spacebox-admin.js/wp-content/plugins/space-boxes/inc/js/spacebox-frontend.jsspace-boxes/inc/css/spacebox-admin.css?ver=space-boxes/inc/css/spacebox-frontend.css?ver=space-boxes/inc/js/spacebox-admin.js?ver=space-boxes/inc/js/spacebox-frontend.js?ver=HTML / DOM Fingerprints
spacebox-galleryspacebox-wrapspacebox-itemspacebox-captiondata-spacebox-idspacebox_frontend_params[spacebox-gallery]