Flipbox Addon for WPBakery Page Builder (formerly Visual Composer) Security & Risk Analysis

wordpress.org/plugins/vc-flipbox

Checkout our Latest WordPress Themes - 100% Free

200 active installs v1.1.8 PHP + WP 4.0.1+ Updated Jul 26, 2021
image-hotspottooltipvisual-composer-pluginvisual-composer-shortcode
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Flipbox Addon for WPBakery Page Builder (formerly Visual Composer) Safe to Use in 2026?

Generally Safe

Score 85/100

Flipbox Addon for WPBakery Page Builder (formerly Visual Composer) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The vc-flipbox plugin v1.1.8 exhibits a generally strong security posture based on the provided static analysis. The absence of any recorded vulnerabilities in its history is a positive indicator. The code analysis reveals no dangerous functions, all SQL queries utilize prepared statements, and the majority of output is properly escaped, suggesting good coding practices. Furthermore, there are no file operations or external HTTP requests, and no taint analysis identified any critical or high severity flows, further reinforcing its secure design.

However, there are a few areas that warrant attention. The plugin has a small attack surface consisting of three shortcodes, and importantly, none of these entry points have explicit authentication or capability checks. While the overall flow analysis did not reveal issues, this lack of authorization on shortcode execution presents a potential risk. A future vulnerability could leverage this lack of checks to execute unintended actions or expose sensitive information, especially if the shortcode logic itself were to contain a flaw that isn't caught by static analysis alone. The absence of nonce checks, while not explicitly penalized if no AJAX is present, is a common security practice that is missing here.

In conclusion, the vc-flipbox plugin v1.1.8 appears to be a securely developed plugin with no historical vulnerabilities and good code hygiene in most areas. The primary concern lies in the unprotected shortcode entry points. While the current codebase doesn't show immediate exploitable flaws, this oversight could become a vector for future attacks. It would be prudent for developers to implement capability checks for these shortcodes to further harden the plugin.

Key Concerns

  • Shortcodes lack authorization checks
  • Missing nonce checks
  • Minor output escaping issues (8% unescaped)
Vulnerabilities
None known

Flipbox Addon for WPBakery Page Builder (formerly Visual Composer) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Flipbox Addon for WPBakery Page Builder (formerly Visual Composer) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
11 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped12 total outputs
Attack Surface

Flipbox Addon for WPBakery Page Builder (formerly Visual Composer) Attack Surface

Entry Points3
Unprotected0

Shortcodes 3

[favc_flipbox] shortcodes\flip-box\flip-box.php:439
[favc_flipbox_advanced] shortcodes\flip-box-advanced\flip-box-advanced.php:1641
[favc_flipbox_two] shortcodes\flip-box-two\flip-box-two.php:453
WordPress Hooks 3
actionadmin_enqueue_scriptsvc-flipbox.php:38
actionadmin_noticesvc-flipbox.php:58
actionadmin_initvc-flipbox.php:68
Maintenance & Trust

Flipbox Addon for WPBakery Page Builder (formerly Visual Composer) Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedJul 26, 2021
PHP min version
Downloads13K

Community Trust

Rating60/100
Number of ratings1
Active installs200
Developer Profile

Flipbox Addon for WPBakery Page Builder (formerly Visual Composer) Developer Profile

themebon

13 plugins · 1K total installs

82
trust score
Avg Security Score
83/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Flipbox Addon for WPBakery Page Builder (formerly Visual Composer)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vc-flipbox/admin/admin.css

HTML / DOM Fingerprints

CSS Classes
hvc_notice
Data Attributes
data-ddd_directiondata-display_asdata-front_imagedata-front_box_colordata-display_icondata-icon_fontawesome+16 more
Shortcode Output
[favc_flipbox][flip-box-two][flip-box-advanced]
FAQ

Frequently Asked Questions about Flipbox Addon for WPBakery Page Builder (formerly Visual Composer)