WooBuilder Security & Risk Analysis

wordpress.org/plugins/woobuilder

WooBuilder lets you take complete control of your product layout, let's you create advanced, professional looking product page layouts.

800 active installs v2.1.0.1 PHP + WP 4.1.0+ Updated Jan 24, 2022
pootle-page-builderpootlepressproduct-builderproduct-page-builderproduct-pagebuilder
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WooBuilder Safe to Use in 2026?

Generally Safe

Score 85/100

WooBuilder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "woobuilder" v2.1.0.1 plugin exhibits a generally good security posture based on the provided static analysis. The absence of detected dangerous functions, raw SQL queries, file operations, and external HTTP requests is a strong positive indicator. The plugin also correctly implements prepared statements for all SQL queries and has some nonce checks in place. However, a significant concern arises from the complete lack of output escaping. This means that any data rendered by the plugin, especially if it originates from user input or external sources, is vulnerable to Cross-Site Scripting (XSS) attacks. The vulnerability history being clear of any recorded CVEs is encouraging, suggesting a history of responsible development. Despite the clean vulnerability history, the unescaped output presents a substantial risk that needs immediate attention to improve the plugin's overall security.

Key Concerns

  • All outputs are unescaped, risking XSS
Vulnerabilities
None known

WooBuilder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WooBuilder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped7 total outputs
Attack Surface

WooBuilder Attack Surface

Entry Points9
Unprotected0

Shortcodes 9

[ppb_product_short_description] inc\class-public.php:43
[ppb_product_price] inc\class-public.php:48
[ppb_product_title] inc\class-public.php:53
[ppb_product_related] inc\class-public.php:58
[ppb_product_images] inc\class-public.php:63
[ppb_product_rating] inc\class-public.php:68
[ppb_product_add_to_cart] inc\class-public.php:73
[ppb_product_tabs] inc\class-public.php:78
[ppb_product_reviews] inc\class-public.php:89
WordPress Hooks 23
filterpootlepb_builder_post_typesinc\class-admin.php:48
actionpootlepb_modulesinc\class-modules.php:27
filterthe_contentinc\class-public.php:81
actionwp_footerinc\class-public.php:181
filterwoocommerce_gallery_image_sizeinc\class-public.php:317
actioninitppb-product-builder.php:120
filterpootlepb_installed_add_onsppb-product-builder.php:140
actionadmin_print_styles-post-new.phpppb-product-builder.php:153
actionadmin_print_styles-post.phpppb-product-builder.php:154
filteradmin_initppb-product-builder.php:156
filtersave_postppb-product-builder.php:157
filterpost_submitbox_misc_actionsppb-product-builder.php:159
filterpootlepb_content_block_tabsppb-product-builder.php:162
filterpootlepb_le_content_block_tabsppb-product-builder.php:164
filterpootlepb_content_block_fieldsppb-product-builder.php:166
filterwc_get_template_partppb-product-builder.php:184
actionpootlepb_live_editor_initppb-product-builder.php:185
actionwp_enqueue_scriptsppb-product-builder.php:190
filterpootlepb_live_page_templateppb-product-builder.php:191
filterwoobuilder_live_product_templateppb-product-builder.php:192
filterpootlepb_dump_ppb_contentppb-product-builder.php:193
actionpootlepb_render_content_blockppb-product-builder.php:195
actionpootlepb_enqueue_admin_scriptsppb-product-builder.php:196
Maintenance & Trust

WooBuilder Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.0
Last updatedJan 24, 2022
PHP min version
Downloads24K

Community Trust

Rating74/100
Number of ratings3
Active installs800
Developer Profile

WooBuilder Developer Profile

pootlepress

9 plugins · 1K total installs

82
trust score
Avg Security Score
83/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WooBuilder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woobuilder/assets/css/admin/woo-builder-admin.css/wp-content/plugins/woobuilder/assets/js/woo-builder-frontend.js/wp-content/plugins/woobuilder/assets/css/woo-builder-frontend.css
Script Paths
/wp-content/plugins/woobuilder/assets/js/woo-builder-frontend.js
Version Parameters
woobuilder/assets/css/admin/woo-builder-admin.css?ver=woobuilder/assets/js/woo-builder-frontend.js?ver=woobuilder/assets/css/woo-builder-frontend.css?ver=

HTML / DOM Fingerprints

CSS Classes
woobuilder-productswoobuilder_single_product_wrapper
Data Attributes
data-woobuilder-iddata-woobuilder-type
JS Globals
woo_builder_params
FAQ

Frequently Asked Questions about WooBuilder