
SQL Chart Builder Security & Risk Analysis
wordpress.org/plugins/sql-chart-builderTurn Your SQL Queries to Beautiful Dynamic Charts- Pie, Line, Area, Donut, Bar Charts with date/input filters.
Is SQL Chart Builder Safe to Use in 2026?
Mostly Safe
Score 77/100SQL Chart Builder is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The "sql-chart-builder" plugin v2.3.7.2 exhibits a generally strong security posture based on static analysis, with no identified dangerous functions, all SQL queries using prepared statements, and a high percentage of properly escaped output. The limited attack surface and robust use of nonces and capability checks are also positive indicators. However, the presence of two known CVEs, with one remaining unpatched, significantly elevates the risk. The historical vulnerability types (XSS and SQL Injection) suggest that input sanitization and output escaping may have been inconsistently applied in past versions, even though current static analysis indicates improvements. This historical pattern, coupled with an unpatched medium-severity vulnerability, warrants careful attention. While the current code appears to follow many best practices, the outstanding vulnerability is a critical concern that undermines the overall security of the plugin.
Key Concerns
- Unpatched CVEs
- Known SQL Injection vulnerabilities
- Known Cross-site Scripting vulnerabilities
SQL Chart Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
SQL Chart Builder <= 2.3.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
SQL Chart Builder <= 2.3.6 - Authenticated (Contributor+) SQL Injection
SQL Chart Builder Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SQL Chart Builder Attack Surface
AJAX Handlers 1
Shortcodes 2
WordPress Hooks 14
Maintenance & Trust
SQL Chart Builder Maintenance & Trust
Maintenance Signals
Community Trust
SQL Chart Builder Alternatives
WP Business Intelligence Lite
wp-business-intelligence-lite
Dynamic web charts and tables for your site! Connect to your live WordPress instance DB to retrieve data in real-time and update charts and tables!
Display SQL Stats
display-sql-stats
! ! ! S T I L L B E T A ! ! !
Database Backup for WordPress
wp-db-backup
Database Backup for WordPress is your one-stop database backup solution for WordPress.
Index WP MySQL For Speed
index-wp-mysql-for-speed
Speed up your WordPress site by adding high-performance keys (database indexes) to your MariaDB / MySQL database tables.
WP phpMyAdmin
wp-phpmyadmin-extension
[ ✅ 𝐒𝐄𝐂𝐔𝐑𝐄 𝐏𝐋𝐔𝐆𝐈𝐍𝐒 𝐵𝓎 𝒫𝓊𝓋𝑜𝓍 ] phpMyAdmin - Database Browser & Manager (for MySQL & MariaDB)
SQL Chart Builder Developer Profile
5 plugins · 700 total installs
How We Detect SQL Chart Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sql-chart-builder/asset/img/recommended1.jpgHTML / DOM Fingerprints
gf-alertgf-alert-infogf-alert-dangerguaven-sqlcharts-noticedata-notice="onboarding_notice"