
WP Layouts Security & Risk Analysis
wordpress.org/plugins/wp-layoutsSave, store and import layouts instantly, all in one place with the click of a button!
Is WP Layouts Safe to Use in 2026?
Generally Safe
Score 92/100WP Layouts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-layouts plugin version 0.6.22 exhibits a mixed security posture. While it demonstrates good practices like using prepared statements for all SQL queries and a high percentage of properly escaped output, significant concerns arise from its attack surface. A substantial number of AJAX handlers (13 out of 19) lack authentication checks, creating potential entry points for unauthorized actions. The presence of the 'unserialize' function is also a notable risk, as improper handling of serialized data can lead to remote code execution vulnerabilities, although no specific flows were flagged as critical or high severity in the taint analysis.
The plugin's vulnerability history is exceptionally clean, with zero recorded CVEs across all severity levels. This absence of past vulnerabilities, coupled with the evident use of prepared statements and nonces (18 checks), suggests a development team that is at least aware of common security pitfalls. However, the static analysis clearly indicates that the attack surface, particularly the unprotected AJAX endpoints, represents the most immediate and concerning risk. The lack of any recorded vulnerabilities does not negate the potential for new ones to emerge, especially given the unprotected entry points.
In conclusion, while the plugin benefits from a clean vulnerability history and strong SQL and output sanitization, the large number of unprotected AJAX endpoints presents a significant weakness. The potential risk associated with the 'unserialize' function also warrants attention. Addressing the unprotected AJAX handlers should be a priority to improve the overall security posture.
Key Concerns
- Unprotected AJAX handlers
- Use of dangerous function: unserialize
WP Layouts Security Vulnerabilities
WP Layouts Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Layouts Attack Surface
AJAX Handlers 19
WordPress Hooks 42
Maintenance & Trust
WP Layouts Maintenance & Trust
Maintenance Signals
Community Trust
WP Layouts Alternatives
Extendify
extendify
The best WordPress templates, pattern, and layout library with 1,000+ designs built for the Gutenberg block editor.
Layouts for WPBakery
layouts-for-wpbakery
Layouts for WPBakery is a beautifully designed free layout for famous WordPress WPBakery page builders.
Post Layouts for Gutenberg
post-layouts
A beautiful post layouts block to showcase your posts in grid and list layout with multiple templates availability.
Layouts for Divi
layouts-for-divi
Layouts for Divi is a beautifully designed free layout for famous WordPress Divi page builders.
Timeline Blocks for Gutenberg
timeline-blocks
A beautiful timeline layout block to showcase your posts in timeline presentation.
WP Layouts Developer Profile
21 plugins · 40K total installs
How We Detect WP Layouts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-layouts/dist/assets/css/ags-layouts-admin.css/wp-content/plugins/wp-layouts/dist/assets/js/ags-layouts-admin.js/wp-content/plugins/wp-layouts/dist/assets/css/ags-layouts-frontend.css/wp-content/plugins/wp-layouts/dist/assets/js/ags-layouts-frontend.js/wp-content/plugins/wp-layouts/includes/previewer.js/wp-content/plugins/wp-layouts/includes/previewer.css/wp-content/plugins/wp-layouts/dist/assets/js/ags-layouts-admin.js/wp-content/plugins/wp-layouts/dist/assets/js/ags-layouts-frontend.js/wp-content/plugins/wp-layouts/includes/previewer.jswp-layouts/dist/assets/css/ags-layouts-admin.css?ver=wp-layouts/dist/assets/js/ags-layouts-admin.js?ver=wp-layouts/dist/assets/css/ags-layouts-frontend.css?ver=wp-layouts/dist/assets/js/ags-layouts-frontend.js?ver=wp-layouts/includes/previewer.js?ver=HTML / DOM Fingerprints
ags-layouts-adminags-layouts-frontendags-layouts-previewerWP Layouts pluginCopyright (C) 2024 WP ZoneThis program is free software: you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,+10 moreags_layouts_previewags_layouts_exportAGSLayoutsAGSLayoutsPreviewerAGSLayoutsSiteImporterAGSLayoutsAccount/wp-json/wp-layouts/v1/layouts