
wpsection Security & Risk Analysis
wordpress.org/plugins/wpsectionwpsection is an Elementor Addon and Theme Making Plugin
Is wpsection Safe to Use in 2026?
Generally Safe
Score 98/100wpsection has a strong security track record. Known vulnerabilities have been patched promptly.
The "wpsection" plugin version 1.5.1 exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, raw SQL queries, and file operations is commendable. Furthermore, the high percentage of properly escaped output and the presence of nonce checks on all AJAX handlers indicate good development practices.
However, a significant concern arises from the plugin's vulnerability history. The presence of a past high-severity vulnerability related to "Improper Control of Filename for Include/Require Statement" (PHP Remote File Inclusion) is a red flag. While this specific vulnerability is currently patched, it suggests a historical tendency towards critical security flaws that could be reintroduced in future versions or exploited in ways not immediately apparent from the static analysis.
The static analysis itself shows a large attack surface with 19 entry points, though all are reported as protected. The lack of explicit capability checks on these entry points, despite the presence of nonce checks for AJAX, warrants careful consideration. This, combined with the historical vulnerability, indicates that while the code adheres to some security best practices, the potential for serious security issues still exists, especially if future updates are not rigorously vetted.
Key Concerns
- Historical high-severity RFI vulnerability
- No capability checks on entry points
wpsection Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WPSection <= 1.3.8 - Authenticated (Contributor+) Local File Inlcusion
wpsection Code Analysis
Output Escaping
Data Flow Analysis
wpsection Attack Surface
AJAX Handlers 8
Shortcodes 11
WordPress Hooks 87
Scheduled Events 1
Maintenance & Trust
wpsection Maintenance & Trust
Maintenance Signals
Community Trust
wpsection Alternatives
wpsection Developer Profile
6 plugins · 4K total installs
How We Detect wpsection
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpsection/plugin/assets/admin/css/style.css/wp-content/plugins/wpsection/plugin/assets/frontend/css/bootstrap.css/wp-content/plugins/wpsection/plugin/assets/admin/js/script.js/wp-content/plugins/wpsection/plugin/assets/frontend/js/bootstrap.min.js/wp-content/plugins/wpsection/plugin/assets/admin/js/script.js/wp-content/plugins/wpsection/plugin/assets/frontend/js/bootstrap.min.jswpsection/style.css?ver=wpsection/script.js?ver=HTML / DOM Fingerprints
wpsection-admin-wrapwpsection-dashboardwpsection-headerwpsection-sidebarwpsection-main-contentwpsection-footerwpsection-settings-formwpsection-element-wrapper<!-- wpsection-admin-wrap --><!-- wpsection-header --><!-- wpsection-sidebar --><!-- wpsection-main-content -->+3 moredata-wpsection-ajaxurldata-wpsection-noncewpsection