Theme Blvd Layouts to Posts Security & Risk Analysis

wordpress.org/plugins/theme-blvd-layouts-to-posts

This plugin extends the Theme Blvd Layout Builder so you can assign your custom templates to standard posts and custom post types.

60 active installs v1.0.5 PHP + WP + Updated Mar 28, 2018
buildercustom-layoutslayout-buildertheme-blvdthemeblvd
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Theme Blvd Layouts to Posts Safe to Use in 2026?

Generally Safe

Score 85/100

Theme Blvd Layouts to Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The security posture of the theme-blvd-layouts-to-posts plugin v1.0.5 appears to be generally strong based on the static analysis. The plugin has a very small attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. Furthermore, all SQL queries are properly prepared, and there are no observed dangerous function calls, file operations, or external HTTP requests. The presence of nonce and capability checks, although minimal in number, is a positive sign. However, a significant concern arises from the complete lack of output escaping, as 100% of the identified outputs are unescaped. This presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities if any user-supplied data is reflected directly in the output without proper sanitization. The plugin's vulnerability history is clean, with no recorded CVEs, which is excellent. This lack of history, combined with the positive code signals, suggests good development practices, but the unescaped output is a critical oversight that requires immediate attention. The strength lies in the limited attack surface and secure SQL practices, while the primary weakness is the potential for XSS due to unescaped output.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Theme Blvd Layouts to Posts Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Theme Blvd Layouts to Posts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
0 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped4 total outputs
Attack Surface

Theme Blvd Layouts to Posts Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_noticestb-layouts-to-posts.php:41
actionadmin_inittb-layouts-to-posts.php:42
actionadd_meta_boxestb-layouts-to-posts.php:47
actionsave_posttb-layouts-to-posts.php:50
filterthemeblvd_frontend_configtb-layouts-to-posts.php:54
actiontemplate_includetb-layouts-to-posts.php:58
actionafter_setup_themetb-layouts-to-posts.php:61
actioninittb-layouts-to-posts.php:71
Maintenance & Trust

Theme Blvd Layouts to Posts Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMar 28, 2018
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

Theme Blvd Layouts to Posts Developer Profile

Jason

22 plugins · 8K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
3363 days
View full developer profile
Detection Fingerprints

How We Detect Theme Blvd Layouts to Posts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/theme-blvd-layouts-to-posts/css/themeblvd-ltp.css/wp-content/plugins/theme-blvd-layouts-to-posts/js/themeblvd-ltp.js
Script Paths
/wp-content/plugins/theme-blvd-layouts-to-posts/js/themeblvd-ltp.js
Version Parameters
theme-blvd-layouts-to-posts/css/themeblvd-ltp.css?ver=theme-blvd-layouts-to-posts/js/themeblvd-ltp.js?ver=

HTML / DOM Fingerprints

CSS Classes
tb-meta-boxtb-options-wrap
Data Attributes
data-tb-custom-layout
FAQ

Frequently Asked Questions about Theme Blvd Layouts to Posts