
Export & Import WPBakery Page Builder Security & Risk Analysis
wordpress.org/plugins/vc-templates-import-exportExport & Import WPBakery Page Builder Templates (Saved Templates/My Templates) in few clicks.
Is Export & Import WPBakery Page Builder Safe to Use in 2026?
Generally Safe
Score 85/100Export & Import WPBakery Page Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "vc-templates-import-export" v1.0.2 exhibits a generally good security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, indicating a limited attack surface. Furthermore, the plugin appears to handle SQL queries securely using prepared statements and has no recorded vulnerabilities or CVEs, suggesting a mature and well-maintained codebase. This lack of historical security issues is a positive indicator.
However, there are notable areas for concern that prevent a completely positive assessment. The most significant is the complete lack of output escaping for all identified outputs (6 in total). This means that any data being displayed to users could potentially be manipulated to inject malicious code, leading to cross-site scripting (XSS) vulnerabilities. Additionally, the plugin performs a file operation without clear evidence of sanitization or validation, which could be a risk if not handled carefully. The absence of any nonce checks or capability checks for potential entry points, while currently showing zero entry points, means that if new entry points are introduced in the future without proper security measures, they would be immediately vulnerable. The lack of taint analysis results is also noted, which might mean the tool couldn't analyze the flows or that there were no detected flows.
In conclusion, while the plugin's minimal attack surface and clean vulnerability history are commendable, the critical flaw of unescaped output presents a substantial risk of XSS vulnerabilities. The file operation, coupled with the absence of input validation and authorization checks on any potential new entry points, adds to the potential for security weaknesses. Addressing the output escaping issue should be a top priority to improve the plugin's security.
Key Concerns
- Unescaped output in 6 instances
- File operation without obvious sanitization
- No nonce checks implemented
- No capability checks implemented
Export & Import WPBakery Page Builder Security Vulnerabilities
Export & Import WPBakery Page Builder Code Analysis
Output Escaping
Export & Import WPBakery Page Builder Attack Surface
WordPress Hooks 5
Maintenance & Trust
Export & Import WPBakery Page Builder Maintenance & Trust
Maintenance Signals
Community Trust
Export & Import WPBakery Page Builder Alternatives
WPBakery Page Builder Addons by Livemesh
addons-for-visual-composer
A collection of 25+ beautifully designed premium quality addons or extensions for WPBakery Page Builder.
Classic Addons – WPBakery Page Builder
classic-addons-wpbakery-page-builder-addons
15+ Beautiful and Powerful Addons for WPBakery Page Builder (Visual Composer)
ChargeWP Timeline Addons For WPBakery Page Builder
chargewp-timeline-addons-for-wpbakery
Power your WPBakery Page Builder with well crafted timeline addons.
Social Elements for WPBakery Page Builder
social-elements-for-wpbakery
A collection of social elements (share buttons, profile links, and more) for WPBakery Page Builder.
Mega Addons For WPBakery Page Builder
mega-addons-for-visual-composer
34+ Addons WPBakery extension, Beautifully designed unique elements, Includes Premium quality addons For WPBakery Page Builder.
Export & Import WPBakery Page Builder Developer Profile
2 plugins · 9K total installs
How We Detect Export & Import WPBakery Page Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vc-templates-import-export/assets/css/admin.cssvc-templates-import-export/assets/css/admin.css?ver=HTML / DOM Fingerprints
tmu-wraptmu-rowtmu-lefttmu-coltmu-col-8tmu-righttmu-col-4tmu-inner+6 moredata-tab