Supreme Addons for Beaver Builder – Security & Risk Analysis

wordpress.org/plugins/supreme-addons-for-beaver-builder-lite

The Supreme Addons for Beaver Builder extends the Beaver Builder functionality with Qr Code Auto Generate modules

50 active installs v1.0.9 PHP + WP 3.6+ Updated Jul 8, 2023
beaver-addonsbeaver-builderbeaver-builder-add-onsbeaver-builder-addonbeaver-builder-free
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEJul 23, 2025
Safety Verdict

Is Supreme Addons for Beaver Builder – Safe to Use in 2026?

Use With Caution

Score 63/100

Supreme Addons for Beaver Builder – has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Jul 23, 2025Updated 2yr ago
Risk Assessment

The plugin exhibits a mixed security posture, with some positive indicators but significant areas of concern. While the static analysis shows no dangerous functions, raw SQL, or external HTTP requests, and all SQL queries use prepared statements, the complete lack of output escaping is a critical weakness. This means that any data processed by the plugin and displayed on the frontend or backend is susceptible to rendering as executable code, potentially leading to cross-site scripting (XSS) attacks. The absence of nonce and capability checks on its single shortcode entry point also raises concerns about authorization and potential abuse.

The vulnerability history reveals a pattern of medium-severity cross-site scripting vulnerabilities, with one currently unpatched. The fact that the last vulnerability was in the near future suggests a potential issue with the provided data's timestamp, but the persistent presence of XSS vulnerabilities is a strong indicator that input sanitization and output encoding are not consistently implemented. This, combined with the static analysis findings, strongly points towards ongoing risks related to XSS.

In conclusion, while the plugin has strengths in its handling of SQL queries and avoiding certain dangerous practices, the pervasive lack of output escaping and the history of XSS vulnerabilities, coupled with insufficient authorization checks, present a significant security risk. The unpatched vulnerability is a clear and present danger that requires immediate attention.

Key Concerns

  • Unpatched CVE
  • No output escaping
  • No nonce checks
  • No capability checks
  • Bundled outdated library (TCPDF)
Vulnerabilities
1 published

Supreme Addons for Beaver Builder – Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-3669medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Supreme Addons for Beaver Builder <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via auto_qrcodesabb Shortcode

Jul 23, 2025Unpatched
Version History

Supreme Addons for Beaver Builder – Release Timeline

v1.0.9Current1 CVE
v1.0.81 CVE
v1.0.71 CVE
v1.0.61 CVE
v1.0.51 CVE
v1.0.41 CVE
v1.0.31 CVE
v1.0.21 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Supreme Addons for Beaver Builder – Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

TCPDF

Output Escaping

0% escaped3 total outputs
Attack Surface

Supreme Addons for Beaver Builder – Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[auto_qrcodesabb] modules\QR-Code\QR-Code.php:105
WordPress Hooks 3
actioninitbb-supreme-addon.php:27
actionadmin_initbb-supreme-addon.php:29
actionadmin_noticesbb-supreme-addon.php:34
Maintenance & Trust

Supreme Addons for Beaver Builder – Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJul 8, 2023
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs50
Developer Profile

Supreme Addons for Beaver Builder – Developer Profile

Mohammed Kalimulla

3 plugins · 160 total installs

82
trust score
Avg Security Score
83/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Supreme Addons for Beaver Builder –

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/supreme-addons-for-beaver-builder-lite/modules/QR-Code/QR-Code.php/wp-content/plugins/supreme-addons-for-beaver-builder-lite/assets/lib/qrlib.php

HTML / DOM Fingerprints

CSS Classes
fl-example-text
Shortcode Output
<img src=
FAQ

Frequently Asked Questions about Supreme Addons for Beaver Builder –