
Vev – Digital Content Creation & Page Builder Security & Risk Analysis
wordpress.org/plugins/vev-designUse the official Vev plugin to easily integrate your page or content and break free from the same old templates.
Is Vev – Digital Content Creation & Page Builder Safe to Use in 2026?
Generally Safe
Score 85/100Vev – Digital Content Creation & Page Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis and vulnerability history, the "vev-design" v2.0.2 plugin appears to have a strong security posture, particularly in its handling of SQL queries and a lack of recorded vulnerabilities. The absence of any identified CVEs and the fact that all SQL queries utilize prepared statements are significant strengths, indicating a commitment to secure coding practices in these critical areas. Furthermore, the plugin boasts a remarkably small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, no unprotected entry points or capability checks were detected. This suggests a well-contained plugin with minimal exposure.
However, the analysis does reveal a notable area of concern: output escaping. With one total output and 0% properly escaped, there is a clear and present risk of Cross-Site Scripting (XSS) vulnerabilities. Any data rendered to the front-end or admin interface that originates from user input or external sources could potentially be exploited. The lack of identified taint flows or dangerous functions is positive, but it doesn't mitigate the output escaping issue. The absence of vulnerability history is reassuring but should not lead to complacency, as the identified output escaping flaw could be a new or as-yet-undiscovered vulnerability.
In conclusion, while "vev-design" v2.0.2 demonstrates excellent security practices in SQL handling and attack surface minimization, the complete lack of output escaping presents a significant risk that needs immediate attention. Addressing this single, critical weakness would drastically improve the plugin's overall security. The plugin's strengths in other areas are commendable, but the unescaped output remains a serious concern.
Key Concerns
- Unescaped output detected
Vev – Digital Content Creation & Page Builder Security Vulnerabilities
Vev – Digital Content Creation & Page Builder Release Timeline
Vev – Digital Content Creation & Page Builder Code Analysis
Output Escaping
Vev – Digital Content Creation & Page Builder Attack Surface
WordPress Hooks 8
Maintenance & Trust
Vev – Digital Content Creation & Page Builder Maintenance & Trust
Maintenance Signals
Community Trust
Vev – Digital Content Creation & Page Builder Alternatives
Page Builder by SiteOrigin
siteorigin-panels
Build responsive page layouts using the widgets you know and love using this simple drag and drop page builder.
Elementor Blocks for Gutenberg
block-builder
Elementor Blocks for Gutenberg, officially created by Elementor Page Builder, allows you to easily insert any Elementor template into Gutenberg.
BlockStrap Page Builder – Bootstrap Blocks
blockstrap-page-builder-blocks
BlockStrap Page Builder - Bootstrap Blocks combines Bootstrap's power with the block editor's versatility.
Landingi Landing Pages
landingi-landing-pages
Create landing pages without any programming skills and import them to your WordPress site using this plugin.
Shape Dividers Plus for Elementor
shape-dividers-plus
Add 20+ extra SVG shape dividers to Elementor sections and containers.
Vev – Digital Content Creation & Page Builder Developer Profile
1 plugin · 50 total installs
How We Detect Vev – Digital Content Creation & Page Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vev-design/build/index.js/wp-content/plugins/vev-design/styles/base.csshttps://embed.vev.page/v1//wp-content/plugins/vev-design/build/index.jsvev-design/build/index.js?ver=vev-design/styles/base.css?ver=HTML / DOM Fingerprints
__vev__alignfull<!-- vev debug: project <!-- vev debug: page data-vev-project-keydata-vev-page-keyvev_api_key/wp-json/vev/v1/settings<div class='__vev__alignfull'><h5>Missing Vev embed code</h5>