
WP Table Builder – Drag & Drop Table Builder Security & Risk Analysis
wordpress.org/plugins/wp-table-builderDrag and Drop Table Builder Plugin. Build Responsive Tables Easily.
Is WP Table Builder – Drag & Drop Table Builder Safe to Use in 2026?
Generally Safe
Score 95/100WP Table Builder – Drag & Drop Table Builder has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "wp-table-builder" v2.1.10 exhibits a mixed security posture. On the positive side, the static analysis shows a strong adherence to secure coding practices regarding SQL queries, with all queries using prepared statements. The output escaping is also very good, with 94% of outputs properly escaped. Furthermore, the attack surface from AJAX handlers and REST API routes is zero, and there are no detected critical or high-severity taint flows. The absence of unpatched CVEs in its history is also a significant strength.
However, several areas raise concerns. The presence of 10 known medium-severity vulnerabilities in its history, including Incorrect Authorization, Cross-site Scripting, and CSRF, indicates a pattern of past security weaknesses that, while currently patched, suggest a higher potential for future disclosures. The complete absence of nonce checks across the entire plugin is a major oversight, especially considering the presence of a shortcode which can be a potential entry point for attacks. While there are capability checks, the lack of nonce validation leaves room for potential cross-site request forgery scenarios. The bundling of Freemius v1.0, if outdated, could also introduce risks.
In conclusion, while "wp-table-builder" has made strides in secure coding for SQL and output handling, the historical prevalence of medium-severity vulnerabilities and the critical omission of nonce checks present notable risks. The plugin's security relies heavily on timely patching of past vulnerabilities, and the lack of nonce protection warrants immediate attention.
Key Concerns
- 10 medium vulnerabilities in history
- No nonce checks
- Bundled library (Freemius v1.0)
WP Table Builder – Drag & Drop Table Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
10 total CVEs
WP Table Builder <= 2.0.19 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Table Creation
WP Table Builder – WordPress Table Plugin <= 2.0.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
WP Table Builder <= 2.0.12 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Table Builder <= 2.0.6 - Cross-Site Request Forgery
WP Table Builder <= 2.0.5 - Reflected Cross-Site Scripting
WP Table Builder – WordPress Table Plugin <= 1.4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Table Builder <= 1.5.0 - Authenticated (Admin+) Stored Cross-Site Scripting
WP Table Builder – WordPress Table Plugin <= 1.4.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Table Builder – WordPress Table Plugin <= 1.4.6 - Authenticated (Admin+) Stored Cross-Site Scripting
WP Table Builder – WordPress Table Plugin <= 1.3.9 - Reflected Cross-Site Scripting
WP Table Builder – Drag & Drop Table Builder Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
WP Table Builder – Drag & Drop Table Builder Attack Surface
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
WP Table Builder – Drag & Drop Table Builder Maintenance & Trust
Maintenance Signals
Community Trust
WP Table Builder – Drag & Drop Table Builder Alternatives
Ninja Tables – Easy Data Table Builder
ninja-tables
Best WordPress table builder plugin packed with versatile features to create fully responsive data tables of any kind.
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin
wpdatatables
The best WordPress table plugin. Create responsive, and searchable tables and charts from Excel (.xlsx, .xls or .ods), CSV, XML, JSON, and PHP.
Data Tables Generator by Supsystic
data-tables-generator-by-supsystic
Create data tables with charts and graphs. Custom design, navigation, searching and ordering functions. Export to PDF, CSV, Print. Excel spreadsheet.
Table Addons for Elementor
table-addons-for-elementor
Table Addons For Elementor is an addon to create table for Elementor page builder. It creates feature rich tables and give options to customize table.
WP Data Access – No-Code App Builder with Tables, Forms, Charts & Maps
wp-data-access
Turn your data into WordPress apps with tables, forms, charts & maps — no code required, with optional hooks for developers. Supports 35+ languages.
WP Table Builder – Drag & Drop Table Builder Developer Profile
1 plugin · 50K total installs
How We Detect WP Table Builder – Drag & Drop Table Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-table-builder/src/editor-common.ts/wp-content/plugins/wp-table-builder/src/editor.scss/wp-content/plugins/wp-table-builder/src/styles.scss/wp-content/plugins/wp-table-builder/src/frontend/common.ts/wp-content/plugins/wp-table-builder/build/index.js/wp-content/plugins/wp-table-builder/build/editor.css/wp-content/plugins/wp-table-builder/src/index.tsx/wp-content/plugins/wp-table-builder/dist/@vite/client/wp-content/plugins/wp-table-builder/dist/@react-refresh/wp-content/plugins/wp-table-builder/dist/src/editor-common.ts/wp-content/plugins/wp-table-builder/dist/src/frontend/common.ts/wp-content/plugins/wp-table-builder/dist/build/index.js/wp-content/plugins/wp-table-builder/dist/src/index.tsx?v=2.1.10HTML / DOM Fingerprints
data-wp-table-builder-settingsWPTB_CFG/wp-json/wp-table-builder/