
Draft – Tailwind CSS for WordPress. Security & Risk Analysis
wordpress.org/plugins/website-builderAdd Tailwind CSS to WordPress, in seconds.
Is Draft – Tailwind CSS for WordPress. Safe to Use in 2026?
Mostly Safe
Score 70/100Draft – Tailwind CSS for WordPress. is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The "website-builder" plugin v3.0.9 exhibits a mixed security posture. On the positive side, the static analysis reveals a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the plugin demonstrates a strong commitment to database security by exclusively using prepared statements for all SQL queries, and it appears to avoid direct file operations and external HTTP requests.
However, significant concerns arise from the output escaping and vulnerability history. The fact that 100% of the single identified output is not properly escaped presents a clear Cross-Site Scripting (XSS) risk. This is further amplified by the plugin's vulnerability history, which shows one known medium-severity CVE for XSS that is currently unpatched. The recency of this vulnerability (2025-09-22) suggests ongoing issues with input sanitization and output encoding.
In conclusion, while the plugin has some foundational security strengths in its limited attack surface and SQL practices, the unpatched XSS vulnerability and the lack of proper output escaping are critical weaknesses that expose users to significant risk. The plugin needs immediate attention to address the identified XSS vulnerability and implement robust output escaping mechanisms.
Key Concerns
- Unpatched CVE (Medium Severity)
- 100% of outputs unescaped
Draft – Tailwind CSS for WordPress. Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Draft <= 3.0.9 - Authenticated (Editor+) Stored Cross-Site Scripting
Draft – Tailwind CSS for WordPress. Code Analysis
Output Escaping
Draft – Tailwind CSS for WordPress. Attack Surface
WordPress Hooks 12
Maintenance & Trust
Draft – Tailwind CSS for WordPress. Maintenance & Trust
Maintenance Signals
Community Trust
Draft – Tailwind CSS for WordPress. Alternatives
WindPress – Tailwind CSS integration for WordPress
windpress
Integrate Tailwind CSS 3 or 4 into WordPress easily, in seconds. Works well with the block editor, page builders, plugins, themes, and custom code.
Aspect Blocks
aspect-blocks
🌐 Aspect Blocks is a Gutenberg plugin that leverages Tailwind CSS for seamless style customization, providing a modern and responsive design. 🌟
Responsive Navigation Block
getdave-responsive-navigation-block
Complete control over your navigation menus based on screen size including styles and menu items.
Visibility Controls for Editor Blocks
visibility-controls-for-editor-blocks
Easily hide or show Gutenberg blocks on mobile, tablet, and desktop devices using customizable breakpoints for responsive design.
Block Enhancements – Extended styling for the Block Editor
block-enhancements
Add icon, responsive spacing, typography, alignment, shadow, transform, transition, color, hover style to blocks. Lightweight, fast, and clean.
Draft – Tailwind CSS for WordPress. Developer Profile
1 plugin · 700 total installs
How We Detect Draft – Tailwind CSS for WordPress.
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/website-builder/build/index.js/wp-content/plugins/website-builder/build/admin.js/wp-content/plugins/website-builder/build/tailwind.cdn.js/wp-content/plugins/website-builder/build/admin.css/wp-content/plugins/website-builder/build/style-index.css/wp-content/plugins/website-builder/build/index.css/wp-content/plugins/website-builder/build/index.js/wp-content/plugins/website-builder/build/admin.js/wp-content/plugins/website-builder/build/tailwind.cdn.jswebsite-builder?ver=website-builder.css?ver=HTML / DOM Fingerprints
draft-component-wrapperdraft-page-builder-settingsdata-draft-settingsdata-draft-componentWebsiteBuilderdraftSettingsdraftComponent/wp-json/website-builder/v1/settings/wp-json/website-builder/v1/get-site-settings/wp-json/website-builder/v1/get-page-settings/wp-json/website-builder/v1/get-all-posts[website_builder][website_builder id=[website_builder title=[website_builder slug=