
UX Flat Security & Risk Analysis
wordpress.org/plugins/ux-flatEnhance user experience with the sleek and modern design provided by the UX Flat plugin for WordPress websites.
Is UX Flat Safe to Use in 2026?
Mostly Safe
Score 73/100UX Flat is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The 'ux-flat' plugin v5.4.0 presents a mixed security picture. On the positive side, the static analysis shows no critical vulnerabilities in terms of dangerous functions, SQL queries are consistently prepared, and a high percentage of output is properly escaped. The absence of file operations and external HTTP requests is also a strength. However, the plugin's attack surface is entirely composed of shortcodes, with a total of 21 entry points, and while no unprotected entry points were found, this reliance solely on shortcodes for user interaction warrants careful consideration.
The vulnerability history is a significant concern, with two known CVEs, one of which remains unpatched and is rated as high severity. The common vulnerability type being Cross-site Scripting (XSS) suggests potential issues with how user input is handled within the shortcodes, despite the generally good output escaping rates. The fact that the last vulnerability was in the future (2026-01-20) is an anomaly in the data, but assuming it refers to a past event, it indicates a recurring pattern of security weaknesses that require attention.
Overall, while the code itself exhibits some good security practices like prepared statements and a decent escaping rate, the unpatched high-severity vulnerability and the reliance on shortcodes as the sole entry point are critical risks. The plugin's past security incidents, particularly XSS, suggest that its input sanitization and handling mechanisms may not be consistently robust, even with the reported output escaping percentages. Users should exercise caution and prioritize patching or migrating away from this plugin.
Key Concerns
- Unpatched high severity CVE
- Known medium severity CVE
- All entry points are shortcodes
- High percentage of outputs not escaped
UX Flat Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
UX Flat <= 5.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
UX Flat <= 4.4 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
UX Flat Code Analysis
Output Escaping
UX Flat Attack Surface
Shortcodes 21
WordPress Hooks 63
Maintenance & Trust
UX Flat Maintenance & Trust
Maintenance Signals
Community Trust
UX Flat Alternatives
UX Ultimate
ux-ultimate
UX Ultimate is a plug-in for WordPress that website using Flatsome theme.
OT Flatsome Vertical Menu
ot-flatsome-vertical-menu
Vertical Menu for Flatsome Woocommerce theme.
Related Posts Flatsome
related-posts-flatsome
Plugin for adding related articles to posts for Flatsome theme.
Mino Flatsome Title With Category
mino-flatsome-title-with-category
Add title with product category element for flatsome theme.
Flatsome pop-up element
pop-up-element-for-flatsome-theme
Add custom pop-up element for Flatsome theme for advertisment
UX Flat Developer Profile
2 plugins · 8K total installs
How We Detect UX Flat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ux-flat/assets/css/icons.min.css/wp-content/plugins/ux-flat/assets/css/fas.min.cssHTML / DOM Fingerprints
icon-zalodata-uxf-typed-stringsUXF_VERSIONUXF_FILEUXF_DIRUXF_URL[ux_menu_link[follow[ux_gallery[ux_slider