
WEN Responsive Columns Security & Risk Analysis
wordpress.org/plugins/wen-responsive-columnsEasily display columnized content in your pages or posts.
Is WEN Responsive Columns Safe to Use in 2026?
Generally Safe
Score 85/100WEN Responsive Columns has a strong security track record. Known vulnerabilities have been patched promptly.
The "wen-responsive-columns" plugin version 1.3.4 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities, unescaped output, file operations, and external HTTP requests is commendable. The plugin also correctly utilizes prepared statements for its SQL queries and performs output escaping for all identified outputs. The presence of capability checks further enhances its security by ensuring proper authorization for certain actions.
However, the plugin's vulnerability history reveals a past medium-severity Cross-Site Scripting (XSS) vulnerability, which, though patched, indicates a potential weakness in input sanitization for web page generation. The lack of explicit nonce checks on any entry points, particularly on the single shortcode, is a notable concern. While the static analysis reports zero unprotected entry points, a shortcode without nonce protection can still be a vector for certain types of attacks if user-supplied data is processed within it without adequate validation and sanitization beyond basic output escaping.
In conclusion, while the current version demonstrates good coding practices in many areas, the historical XSS vulnerability and the absence of nonce checks on its shortcode represent areas where further scrutiny and potential hardening are advisable. The plugin's strengths lie in its secure handling of database queries and output, but the potential for client-side manipulation through its shortcode warrants careful consideration.
Key Concerns
- Past medium XSS vulnerability
- Missing nonce checks on shortcode
WEN Responsive Columns Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WEN Responsive Columns <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
WEN Responsive Columns Code Analysis
Bundled Libraries
Output Escaping
WEN Responsive Columns Attack Surface
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
WEN Responsive Columns Maintenance & Trust
Maintenance Signals
Community Trust
WEN Responsive Columns Alternatives
Block Editor Bootstrap Blocks
block-editor-bootstrap-blocks
Fully responsive Bootstrap 5 blocks, components and extends for Gutenberg
Advanced Columns Block: Layout builder
advanced-columns-block
The professional plugin for creating responsive layouts in WordPress.
PixGridder
pixgridder
A simple page grid composer that splits your pages into ordered grids, a builder for rows and columns
Responsive Columns
responsive-columns
Adaptive column counts, gap controls, and Masonry layouts for core Columns and Query Loop blocks — no custom blocks required.
Grid Blocks
grid-blocks
Gutenberg blocks for creating responsive grid rows, columns, and block grids.
WEN Responsive Columns Developer Profile
63 plugins · 35K total installs
How We Detect WEN Responsive Columns
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wen-responsive-columns/admin/css/wen-responsive-columns-admin.css/wp-content/plugins/wen-responsive-columns/admin/js/wen-responsive-columns-admin.js/wp-content/plugins/wen-responsive-columns/admin/js/wen-responsive-columns-tinymce-plugin.js/wp-content/plugins/wen-responsive-columns/includes/js/wen-responsive-columns-public.js/wp-content/plugins/wen-responsive-columns/includes/css/wen-responsive-columns-public.css/wp-content/plugins/wen-responsive-columns/admin/js/wen-responsive-columns-tinymce-plugin.jswen-responsive-columns/admin/css/wen-responsive-columns-admin.css?ver=wen-responsive-columns/admin/js/wen-responsive-columns-admin.js?ver=wen-responsive-columns/admin/js/wen-responsive-columns-tinymce-plugin.js?ver=wen-responsive-columns/includes/js/wen-responsive-columns-public.js?ver=wen-responsive-columns/includes/css/wen-responsive-columns-public.css?ver=HTML / DOM Fingerprints
wrc-form-contentwrc-form-rowwrc-column-mix-wrapwrc-column-mixid="wrc-popup-form"id="wrc-grid"id="wrc-column-number"id="wrc-column-mix-wrap"id="wrc-column-mix"id="wrc-submit"tinymce[wrc_columns[/wrc_columns]