Supreme Addons for Beaver Builder – Security & Risk Analysis

wordpress.org/plugins/supreme-addons-for-beaver-builder-lite

The Supreme Addons for Beaver Builder extends the Beaver Builder functionality with Qr Code Auto Generate modules

50 active installs v1.0.9 PHP + WP 3.6+ Updated Unknown
beaver-addonsbeaver-builderbeaver-builder-add-onsbeaver-builder-addonbeaver-builder-free
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEJul 23, 2025
Safety Verdict

Is Supreme Addons for Beaver Builder – Safe to Use in 2026?

Mostly Safe

Score 78/100

Supreme Addons for Beaver Builder – is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Jul 23, 2025
Risk Assessment

The plugin exhibits a mixed security posture, with some positive indicators but significant areas of concern. While the static analysis shows no dangerous functions, raw SQL, or external HTTP requests, and all SQL queries use prepared statements, the complete lack of output escaping is a critical weakness. This means that any data processed by the plugin and displayed on the frontend or backend is susceptible to rendering as executable code, potentially leading to cross-site scripting (XSS) attacks. The absence of nonce and capability checks on its single shortcode entry point also raises concerns about authorization and potential abuse.

The vulnerability history reveals a pattern of medium-severity cross-site scripting vulnerabilities, with one currently unpatched. The fact that the last vulnerability was in the near future suggests a potential issue with the provided data's timestamp, but the persistent presence of XSS vulnerabilities is a strong indicator that input sanitization and output encoding are not consistently implemented. This, combined with the static analysis findings, strongly points towards ongoing risks related to XSS.

In conclusion, while the plugin has strengths in its handling of SQL queries and avoiding certain dangerous practices, the pervasive lack of output escaping and the history of XSS vulnerabilities, coupled with insufficient authorization checks, present a significant security risk. The unpatched vulnerability is a clear and present danger that requires immediate attention.

Key Concerns

  • Unpatched CVE
  • No output escaping
  • No nonce checks
  • No capability checks
  • Bundled outdated library (TCPDF)
Vulnerabilities
1

Supreme Addons for Beaver Builder – Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-3669medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Supreme Addons for Beaver Builder <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via auto_qrcodesabb Shortcode

Jul 23, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Supreme Addons for Beaver Builder – Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

TCPDF

Output Escaping

0% escaped3 total outputs
Attack Surface

Supreme Addons for Beaver Builder – Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[auto_qrcodesabb] modules\QR-Code\QR-Code.php:105
WordPress Hooks 3
actioninitbb-supreme-addon.php:27
actionadmin_initbb-supreme-addon.php:29
actionadmin_noticesbb-supreme-addon.php:34
Maintenance & Trust

Supreme Addons for Beaver Builder – Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedUnknown
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs50
Developer Profile

Supreme Addons for Beaver Builder – Developer Profile

Mohammed Kalimulla

3 plugins · 160 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Supreme Addons for Beaver Builder –

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/supreme-addons-for-beaver-builder-lite/modules/QR-Code/QR-Code.php/wp-content/plugins/supreme-addons-for-beaver-builder-lite/assets/lib/qrlib.php

HTML / DOM Fingerprints

CSS Classes
fl-example-text
Shortcode Output
<img src=
FAQ

Frequently Asked Questions about Supreme Addons for Beaver Builder –