Vev – Digital Content Creation & Page Builder Security & Risk Analysis

wordpress.org/plugins/vev-design

Use the official Vev plugin to easily integrate your page or content and break free from the same old templates.

50 active installs v2.0.2 PHP + WP + Updated May 3, 2023
block-builderdesignembedno-codepage-builder
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Vev – Digital Content Creation & Page Builder Safe to Use in 2026?

Generally Safe

Score 85/100

Vev – Digital Content Creation & Page Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

Based on the static analysis and vulnerability history, the "vev-design" v2.0.2 plugin appears to have a strong security posture, particularly in its handling of SQL queries and a lack of recorded vulnerabilities. The absence of any identified CVEs and the fact that all SQL queries utilize prepared statements are significant strengths, indicating a commitment to secure coding practices in these critical areas. Furthermore, the plugin boasts a remarkably small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, no unprotected entry points or capability checks were detected. This suggests a well-contained plugin with minimal exposure.

However, the analysis does reveal a notable area of concern: output escaping. With one total output and 0% properly escaped, there is a clear and present risk of Cross-Site Scripting (XSS) vulnerabilities. Any data rendered to the front-end or admin interface that originates from user input or external sources could potentially be exploited. The lack of identified taint flows or dangerous functions is positive, but it doesn't mitigate the output escaping issue. The absence of vulnerability history is reassuring but should not lead to complacency, as the identified output escaping flaw could be a new or as-yet-undiscovered vulnerability.

In conclusion, while "vev-design" v2.0.2 demonstrates excellent security practices in SQL handling and attack surface minimization, the complete lack of output escaping presents a significant risk that needs immediate attention. Addressing this single, critical weakness would drastically improve the plugin's overall security. The plugin's strengths in other areas are commendable, but the unescaped output remains a serious concern.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Vev – Digital Content Creation & Page Builder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Vev – Digital Content Creation & Page Builder Release Timeline

v2.0.2Current
v2.0.1
v1.6.9
v1.4.1
v1.4.0
v1.3.1
v1.3.0
v1.2.1
v1.2.0
v1.1.7
v1.1.6
v1.1.5
v1.1.4
v1.1.3
v1.1.2
v1.1.1
v1.1.0
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Vev – Digital Content Creation & Page Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Vev – Digital Content Creation & Page Builder Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionwp_headvev.block.php:17
actionrest_api_initvev.block.php:31
actionadmin_initvev.block.php:32
actioninitvev.block.php:87
filtertheme_page_templatesvev.templates.php:56
filtertheme_post_templatesvev.templates.php:57
filterwp_insert_post_datavev.templates.php:58
filtertemplate_includevev.templates.php:59
Maintenance & Trust

Vev – Digital Content Creation & Page Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedMay 3, 2023
PHP min version
Downloads70K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Vev – Digital Content Creation & Page Builder Developer Profile

Vev

1 plugin · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Vev – Digital Content Creation & Page Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vev-design/build/index.js/wp-content/plugins/vev-design/styles/base.css
Script Paths
https://embed.vev.page/v1//wp-content/plugins/vev-design/build/index.js
Version Parameters
vev-design/build/index.js?ver=vev-design/styles/base.css?ver=

HTML / DOM Fingerprints

CSS Classes
__vev__alignfull
HTML Comments
<!-- vev debug: project <!-- vev debug: page
Data Attributes
data-vev-project-keydata-vev-page-key
JS Globals
vev_api_key
REST Endpoints
/wp-json/vev/v1/settings
Shortcode Output
<div class='__vev__alignfull'><h5>Missing Vev embed code</h5>
FAQ

Frequently Asked Questions about Vev – Digital Content Creation & Page Builder