SV Columns Manager Security & Risk Analysis

wordpress.org/plugins/sv-columns-manager

SV Columns Manager lets you control how columns behave on responsive devices.

10 active installs v2.0.00 PHP 8.0+ WP 6.0+ Updated May 24, 2023
columns-breakpointcolumns-managercolumns-mobilecolumns-style
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SV Columns Manager Safe to Use in 2026?

Generally Safe

Score 85/100

SV Columns Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The sv-columns-manager plugin version 2.0.00 exhibits a generally strong security posture, with no known vulnerabilities in its history and a good approach to SQL query sanitization. The code analysis reveals no critical or high-severity taint flows, and all SQL queries utilize prepared statements. Furthermore, the plugin employs nonces and capability checks, indicating an awareness of common WordPress security practices.

However, a significant concern lies within its attack surface. While the total number of entry points is relatively low, one of the four AJAX handlers lacks any authentication checks. This unprotected entry point presents a potential risk, as it could be leveraged by unauthenticated users to trigger unintended actions. Additionally, the plugin's output escaping is only moderately effective, with a substantial portion of outputs not being properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully.

In conclusion, sv-columns-manager 2.0.00 demonstrates several positive security attributes, particularly in its handling of database interactions and its proactive use of security nonces and capability checks. Nevertheless, the presence of an unprotected AJAX handler and the incomplete output escaping are notable weaknesses that warrant attention to mitigate potential security risks.

Key Concerns

  • AJAX handler without auth check
  • Moderate output escaping (27% proper)
Vulnerabilities
None known

SV Columns Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

SV Columns Manager Release Timeline

v2.0.00Current
v1.9.00
v1.8.03
v1.8.02
v1.8.01
v1.5.15
v1.5.14
v1.5.13
Code Analysis
Analyzed Apr 16, 2026

SV Columns Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
356
134 escaped
Nonce Checks
5
Capability Checks
9
File Operations
2
External Requests
2
Bundled Libraries
0

Output Escaping

27% escaped490 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
clear_cache_link (src/core_plugin/core/scripts/scripts.php:147)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

SV Columns Manager Attack Surface

Entry Points4
Unprotected1

AJAX Handlers 4

authwp_ajax_sv_core_gutenberg_save_post_update_metaboxessrc/core_plugin/core/core.php:58
authwp_ajax_sv_core_expert_modesrc/core_plugin/core/core.php:446
authwp_ajax_sv_ajax_get_sectionsrc/core_plugin/core/core.php:448
authwp_ajax_sv_ajax_settings_save_formsrc/core_plugin/core/core.php:450
WordPress Hooks 40
actionwp_enqueue_scriptssrc/blocks/wrapper/index.php:17
actionadmin_noticessrc/core_plugin/core/abstract.php:105
actionplugins_loadedsrc/core_plugin/core/abstract.php:335
actionadmin_initsrc/core_plugin/core/core.php:109
actionwp_footersrc/core_plugin/core/core.php:363
actionplugins_loadedsrc/core_plugin/core/core.php:431
actioninitsrc/core_plugin/core/core.php:453
actioninitsrc/core_plugin/core/core.php:500
actionload-post.phpsrc/core_plugin/core/metabox/metabox.php:56
actionload-post-new.phpsrc/core_plugin/core/metabox/metabox.php:57
actionadd_meta_boxessrc/core_plugin/core/metabox/metabox.php:66
actionsave_postsrc/core_plugin/core/metabox/metabox.php:67
actionenqueue_block_editor_assetssrc/core_plugin/core/scripts/scripts.php:57
actionadmin_initsrc/core_plugin/core/scripts/scripts.php:61
actionadmin_enqueue_scriptssrc/core_plugin/core/scripts/scripts.php:62
actionadmin_enqueue_scriptssrc/core_plugin/core/scripts/scripts.php:63
actionwp_enqueue_scriptsrc/core_plugin/core/scripts/scripts.php:65
actionwp_enqueue_scriptssrc/core_plugin/core/scripts/scripts.php:66
actionwp_enqueue_scriptssrc/core_plugin/core/scripts/scripts.php:67
actiontemplate_redirectsrc/core_plugin/core/scripts/scripts.php:69
actiontemplate_redirectsrc/core_plugin/core/scripts/scripts.php:70
actionwp_footersrc/core_plugin/core/scripts/scripts.php:71
actionwp_footersrc/core_plugin/core/scripts/scripts.php:72
filterscript_loader_tagsrc/core_plugin/core/scripts/scripts.php:74
actionadmin_bar_menusrc/core_plugin/core/scripts/scripts.php:105
actionupdated_optionsrc/core_plugin/core/scripts/scripts.php:214
actionwp_footersrc/core_plugin/core/scripts/scripts.php:309
actionwp_print_footer_scriptssrc/core_plugin/core/scripts/scripts.php:341
actionwp_footersrc/core_plugin/core/scripts/scripts.php:610
actionadmin_footersrc/core_plugin/core/scripts/scripts.php:932
actionafter_setup_themesrc/core_plugin/core/settings/modules/setting_box_shadow/setting_box_shadow.php:11
actionafter_setup_themesrc/core_plugin/core/settings/modules/setting_color/setting_color.php:15
actionsv_core_module_scripts_loadedsrc/core_plugin/core/settings/modules/setting_color/setting_color.php:128
actionwidgets_initsrc/core_plugin/core/widgets/widgets.php:91
actionadmin_menusrc/core_plugin/core_plugin.php:13
actionadmin_menusrc/core_plugin/core_plugin.php:14
actionadmin_noticessrc/core_plugin/dependencies/sv_dependencies.php:32
actionadmin_noticessrc/core_plugin/dependencies/sv_dependencies.php:44
actionafter_switch_themesrc/core_plugin/dependencies/sv_dependencies.php:54
actioninitsrc/core_plugin/dependencies/sv_dependencies.php:61
Maintenance & Trust

SV Columns Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedMay 24, 2023
PHP min version8.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

SV Columns Manager Alternatives

No alternatives data available yet.

Developer Profile

SV Columns Manager Developer Profile

straightvisions GmbH

12 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SV Columns Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sv-columns-manager/src/blocks/wrapper/view.js/wp-content/plugins/sv-columns-manager/src/blocks/wrapper/style.css/wp-content/plugins/sv-columns-manager/src/blocks/wrapper/editor.css
Script Paths
/wp-content/plugins/sv-columns-manager/src/blocks/wrapper/view.js
Version Parameters
sv-columns-manager/src/blocks/wrapper/view.js?ver=sv-columns-manager/src/blocks/wrapper/style.css?ver=sv-columns-manager/src/blocks/wrapper/editor.css?ver=

HTML / DOM Fingerprints

CSS Classes
svcm-lg-svcm-md-v-svcm-md-h-svcm-sm-v-svcm-sm-h-svcm-xs-v-svcm-xs-h-
FAQ

Frequently Asked Questions about SV Columns Manager