Export & Import WPBakery Page Builder Security & Risk Analysis

wordpress.org/plugins/vc-templates-import-export

Export & Import WPBakery Page Builder Templates (Saved Templates/My Templates) in few clicks.

9K active installs v1.0.2 PHP 5.6+ WP 4.4+ Updated Nov 7, 2023
wpbwpbakerywpbakery-page-builderwpbakery-page-builder-addon
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Export & Import WPBakery Page Builder Safe to Use in 2026?

Generally Safe

Score 85/100

Export & Import WPBakery Page Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The plugin "vc-templates-import-export" v1.0.2 exhibits a generally good security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, indicating a limited attack surface. Furthermore, the plugin appears to handle SQL queries securely using prepared statements and has no recorded vulnerabilities or CVEs, suggesting a mature and well-maintained codebase. This lack of historical security issues is a positive indicator.

However, there are notable areas for concern that prevent a completely positive assessment. The most significant is the complete lack of output escaping for all identified outputs (6 in total). This means that any data being displayed to users could potentially be manipulated to inject malicious code, leading to cross-site scripting (XSS) vulnerabilities. Additionally, the plugin performs a file operation without clear evidence of sanitization or validation, which could be a risk if not handled carefully. The absence of any nonce checks or capability checks for potential entry points, while currently showing zero entry points, means that if new entry points are introduced in the future without proper security measures, they would be immediately vulnerable. The lack of taint analysis results is also noted, which might mean the tool couldn't analyze the flows or that there were no detected flows.

In conclusion, while the plugin's minimal attack surface and clean vulnerability history are commendable, the critical flaw of unescaped output presents a substantial risk of XSS vulnerabilities. The file operation, coupled with the absence of input validation and authorization checks on any potential new entry points, adds to the potential for security weaknesses. Addressing the output escaping issue should be a top priority to improve the plugin's security.

Key Concerns

  • Unescaped output in 6 instances
  • File operation without obvious sanitization
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Export & Import WPBakery Page Builder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Export & Import WPBakery Page Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped6 total outputs
Attack Surface

Export & Import WPBakery Page Builder Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninitvc-templates-import-export.php:29
actionadmin_menuvc-templates-import-export.php:36
actionadmin_enqueue_scriptsvc-templates-import-export.php:37
actionadmin_noticesvc-templates-import-export.php:51
filterupload_mimesvc-templates-import-export.php:182
Maintenance & Trust

Export & Import WPBakery Page Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedNov 7, 2023
PHP min version5.6
Downloads107K

Community Trust

Rating100/100
Number of ratings12
Active installs9K
Developer Profile

Export & Import WPBakery Page Builder Developer Profile

Khoapq

2 plugins · 9K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Export & Import WPBakery Page Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vc-templates-import-export/assets/css/admin.css
Version Parameters
vc-templates-import-export/assets/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
tmu-wraptmu-rowtmu-lefttmu-coltmu-col-8tmu-righttmu-col-4tmu-inner+6 more
Data Attributes
data-tab
FAQ

Frequently Asked Questions about Export & Import WPBakery Page Builder