
Supreme Addons for Beaver Builder – Security & Risk Analysis
wordpress.org/plugins/supreme-addons-for-beaver-builder-liteThe Supreme Addons for Beaver Builder extends the Beaver Builder functionality with Qr Code Auto Generate modules
Is Supreme Addons for Beaver Builder – Safe to Use in 2026?
Mostly Safe
Score 78/100Supreme Addons for Beaver Builder – is generally safe to use. 1 past CVE were resolved. Keep it updated.
The plugin exhibits a mixed security posture, with some positive indicators but significant areas of concern. While the static analysis shows no dangerous functions, raw SQL, or external HTTP requests, and all SQL queries use prepared statements, the complete lack of output escaping is a critical weakness. This means that any data processed by the plugin and displayed on the frontend or backend is susceptible to rendering as executable code, potentially leading to cross-site scripting (XSS) attacks. The absence of nonce and capability checks on its single shortcode entry point also raises concerns about authorization and potential abuse.
The vulnerability history reveals a pattern of medium-severity cross-site scripting vulnerabilities, with one currently unpatched. The fact that the last vulnerability was in the near future suggests a potential issue with the provided data's timestamp, but the persistent presence of XSS vulnerabilities is a strong indicator that input sanitization and output encoding are not consistently implemented. This, combined with the static analysis findings, strongly points towards ongoing risks related to XSS.
In conclusion, while the plugin has strengths in its handling of SQL queries and avoiding certain dangerous practices, the pervasive lack of output escaping and the history of XSS vulnerabilities, coupled with insufficient authorization checks, present a significant security risk. The unpatched vulnerability is a clear and present danger that requires immediate attention.
Key Concerns
- Unpatched CVE
- No output escaping
- No nonce checks
- No capability checks
- Bundled outdated library (TCPDF)
Supreme Addons for Beaver Builder – Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Supreme Addons for Beaver Builder <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via auto_qrcodesabb Shortcode
Supreme Addons for Beaver Builder – Code Analysis
Bundled Libraries
Output Escaping
Supreme Addons for Beaver Builder – Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Supreme Addons for Beaver Builder – Maintenance & Trust
Maintenance Signals
Community Trust
Supreme Addons for Beaver Builder – Alternatives
PowerPack Lite for Beaver Builder
powerpack-addon-for-beaver-builder
PowerPack Lite for Beaver Builder extends Beaver Builder with custom options, unique modules and templates.
Xpro Addons For Beaver Builder – Lite
xpro-addons-beaver-builder-elementor
Xpro Addons for Beaver Builder – Lite is a simple drag-and-drop creative module pack that lets you create stunning websites.
Image Carousel Addon for Beaver Builder
image-carousel-addon-for-beaver-builder
A quick and easy responsive image carousel module for Beaver Builder.
Ultimate Addons for Beaver Builder – Lite
ultimate-addons-for-beaver-builder-lite
Extend Beaver Builder with powerful modules and ready-made templates to build stunning WordPress websites faster.
Bridge Addons for Beaver Builder
bridge-addons
Bridge Addons plugin extends your Beaver Builder plugin with advanced modules.
Supreme Addons for Beaver Builder – Developer Profile
3 plugins · 160 total installs
How We Detect Supreme Addons for Beaver Builder –
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/supreme-addons-for-beaver-builder-lite/modules/QR-Code/QR-Code.php/wp-content/plugins/supreme-addons-for-beaver-builder-lite/assets/lib/qrlib.phpHTML / DOM Fingerprints
fl-example-text<img src=