Xpro Theme Builder For Elementor – FREE Security & Risk Analysis

wordpress.org/plugins/xpro-theme-builder

Try FREE Theme Builder for Elementor with 50+ FREE widgets. Create a custom header, footer, singular, and archive layout in no time.

10K active installs v1.2.11 PHP 7.0+ WP 5.0+ Updated Sep 4, 2025
elementorfree-theme-builderheader-footer-buildersticky-headertheme-builder
98
A · Safe
CVEs total2
Unpatched0
Last CVEAug 27, 2025
Safety Verdict

Is Xpro Theme Builder For Elementor – FREE Safe to Use in 2026?

Generally Safe

Score 98/100

Xpro Theme Builder For Elementor – FREE has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Aug 27, 2025Updated 8mo ago
Risk Assessment

The "xpro-theme-builder" v1.2.11 plugin exhibits a mixed security posture. On the positive side, static analysis reveals a strong adherence to secure coding practices with no dangerous functions identified, 100% of SQL queries utilizing prepared statements, and a good percentage of output properly escaped. The presence of nonce and capability checks, along with the absence of direct file operations or external HTTP requests, further indicates a generally secure codebase. However, a significant concern arises from its vulnerability history, which shows two medium-severity CVEs, both related to missing authorization. While currently unpatched vulnerabilities are zero, the pattern of past authorization issues, even if resolved, suggests a recurring weakness that demands ongoing vigilance.

The attack surface is relatively small and, crucially, appears to be entirely protected by authentication and permission checks, which is a very positive finding. The lack of identified taint flows with unsanitized paths is also reassuring. The only minor area for potential improvement identified in the static analysis is the 81% output escaping rate; striving for 100% would eliminate any residual risk of XSS in the remaining 19% of outputs.

In conclusion, while the current code version seems to have addressed its past vulnerabilities and demonstrates good general security practices, the historical presence of missing authorization vulnerabilities cannot be ignored. This suggests a past weakness that could potentially resurface if not diligently managed and reviewed in future updates. The plugin is generally secure for its current version, but the historical pattern warrants a slightly cautious approach.

Key Concerns

  • Two medium severity CVEs in history
  • 81% output escaping, potential XSS risk
Vulnerabilities
2 published

Xpro Theme Builder For Elementor – FREE Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-58198medium · 4.3Missing Authorization

Xpro Theme Builder <= 1.2.9 - Missing Authorization

Aug 27, 2025 Patched in 1.2.10 (8d)
CVE-2025-32201medium · 4.3Missing Authorization

Xpro Theme Builder <= 1.2.8.4 - Missing Authorization

Apr 4, 2025 Patched in 1.2.8.5 (34d)
Version History

Xpro Theme Builder For Elementor – FREE Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Xpro Theme Builder For Elementor – FREE Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
48 escaped
Nonce Checks
1
Capability Checks
10
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

81% escaped59 total outputs
Attack Surface

Xpro Theme Builder For Elementor – FREE Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[xpro_theme_builder_template] plugin.php:83
[xpro_comments_template] plugin.php:92
WordPress Hooks 154
actioninitadmin\class-xpro-admin.php:30
actioninitadmin\class-xpro-admin.php:31
actionadd_meta_boxesadmin\class-xpro-admin.php:32
actionsave_postadmin\class-xpro-admin.php:33
actiontemplate_redirectadmin\class-xpro-admin.php:34
actionadmin_menuadmin\class-xpro-admin.php:35
filtermanage_xpro-themer_posts_columnsadmin\class-xpro-admin.php:36
actionmanage_xpro-themer_posts_custom_columnadmin\class-xpro-admin.php:37
actionmanage_xpro-themer_posts_custom_columnadmin\class-xpro-admin.php:38
filtermanage_xpro-themer_posts_columnsadmin\class-xpro-admin.php:39
actionadmin_headadmin\class-xpro-admin.php:40
actionelementor/editor/footeradmin\class-xpro-admin.php:45
actionrest_api_initadmin\class-xpro-rest-api.php:25
actionelementor/element/after_section_endinc\header-sticky.php:28
actionelementor/element/after_section_endinc\header-sticky.php:29
filterxpro_theme_builder_get_settings_type_headerinc\wpml-compatibility.php:38
filterxpro_theme_builder_get_settings_type_footerinc\wpml-compatibility.php:39
filterxpro_theme_builder_get_settings_type_singularinc\wpml-compatibility.php:40
filterxpro_theme_builder_get_settings_type_archiveinc\wpml-compatibility.php:41
filterxpro_theme_builder_render_template_idinc\wpml-compatibility.php:42
actionwp_enqueue_scriptsplugin.php:75
actionadmin_enqueue_scriptsplugin.php:76
filterbody_classplugin.php:77
filterplugin_row_metaplugin.php:80
actioninitplugin.php:86
actionelementor/documents/registerplugin.php:89
actionwpthemes\class-astra-compatibility.php:27
filtersingle_templatethemes\class-astra-compatibility.php:39
actionastra_headerthemes\class-astra-compatibility.php:58
actionastra_footerthemes\class-astra-compatibility.php:70
filterpage_templatethemes\class-astra-compatibility.php:77
filtersingle_templatethemes\class-astra-compatibility.php:78
filter404_templatethemes\class-astra-compatibility.php:79
filterfrontpage_templatethemes\class-astra-compatibility.php:80
actiontemplate_redirectthemes\class-astra-compatibility.php:83
actiontemplate_includethemes\class-astra-compatibility.php:84
filtersearch_templatethemes\class-astra-compatibility.php:92
filterdate_templatethemes\class-astra-compatibility.php:93
filterauthor_templatethemes\class-astra-compatibility.php:94
filterarchive_templatethemes\class-astra-compatibility.php:95
filtercategory_templatethemes\class-astra-compatibility.php:96
filtertag_templatethemes\class-astra-compatibility.php:97
filterhome_templatethemes\class-astra-compatibility.php:98
actiontemplate_redirectthemes\class-astra-compatibility.php:101
actiontemplate_includethemes\class-astra-compatibility.php:102
filterastra_the_title_enabledthemes\class-astra-compatibility.php:120
filterastra_the_title_enabledthemes\class-astra-compatibility.php:123
filterastra_page_layoutthemes\class-astra-compatibility.php:134
filterastra_get_content_layoutthemes\class-astra-compatibility.php:149
filterastra_footer_sml_layoutthemes\class-astra-compatibility.php:164
filterastra_advanced_footer_disablethemes\class-astra-compatibility.php:179
filterastra_main_header_displaythemes\class-astra-compatibility.php:195
actionwpthemes\class-default-compatibility.php:27
filtersingle_templatethemes\class-default-compatibility.php:39
actionget_headerthemes\class-default-compatibility.php:44
actionxpro_headerthemes\class-default-compatibility.php:45
actionget_footerthemes\class-default-compatibility.php:49
actionxpro_footerthemes\class-default-compatibility.php:50
filterpage_templatethemes\class-default-compatibility.php:55
filtersingle_templatethemes\class-default-compatibility.php:56
filter404_templatethemes\class-default-compatibility.php:57
filterfrontpage_templatethemes\class-default-compatibility.php:58
actiontemplate_redirectthemes\class-default-compatibility.php:61
actiontemplate_includethemes\class-default-compatibility.php:62
filtersearch_templatethemes\class-default-compatibility.php:68
filterdate_templatethemes\class-default-compatibility.php:69
filterauthor_templatethemes\class-default-compatibility.php:70
filterarchive_templatethemes\class-default-compatibility.php:71
filtercategory_templatethemes\class-default-compatibility.php:72
filtertag_templatethemes\class-default-compatibility.php:73
filterhome_templatethemes\class-default-compatibility.php:74
actiontemplate_redirectthemes\class-default-compatibility.php:77
actiontemplate_includethemes\class-default-compatibility.php:78
actionwpthemes\class-generatepress-compatibility.php:29
filtersingle_templatethemes\class-generatepress-compatibility.php:41
actiongenerate_headerthemes\class-generatepress-compatibility.php:47
actiongenerate_footerthemes\class-generatepress-compatibility.php:53
filtergenerate_page_classthemes\class-generatepress-compatibility.php:62
filterpage_templatethemes\class-generatepress-compatibility.php:63
filtersingle_templatethemes\class-generatepress-compatibility.php:64
filter404_templatethemes\class-generatepress-compatibility.php:65
filterfrontpage_templatethemes\class-generatepress-compatibility.php:66
actiontemplate_redirectthemes\class-generatepress-compatibility.php:69
actiontemplate_includethemes\class-generatepress-compatibility.php:70
filtergenerate_page_classthemes\class-generatepress-compatibility.php:80
filtersearch_templatethemes\class-generatepress-compatibility.php:81
filterdate_templatethemes\class-generatepress-compatibility.php:82
filterauthor_templatethemes\class-generatepress-compatibility.php:83
filterarchive_templatethemes\class-generatepress-compatibility.php:84
filtercategory_templatethemes\class-generatepress-compatibility.php:85
filtertag_templatethemes\class-generatepress-compatibility.php:86
filterhome_templatethemes\class-generatepress-compatibility.php:87
actiontemplate_redirectthemes\class-generatepress-compatibility.php:90
actiontemplate_includethemes\class-generatepress-compatibility.php:91
actionwpthemes\class-megaone-compatibility.php:27
filtersingle_templatethemes\class-megaone-compatibility.php:39
actionmegaone_headerthemes\class-megaone-compatibility.php:48
actionmegaone_footerthemes\class-megaone-compatibility.php:53
filterpage_templatethemes\class-megaone-compatibility.php:61
filtersingle_templatethemes\class-megaone-compatibility.php:62
filter404_templatethemes\class-megaone-compatibility.php:63
filterfrontpage_templatethemes\class-megaone-compatibility.php:64
actiontemplate_redirectthemes\class-megaone-compatibility.php:67
actiontemplate_includethemes\class-megaone-compatibility.php:68
filtersearch_templatethemes\class-megaone-compatibility.php:78
filterdate_templatethemes\class-megaone-compatibility.php:79
filterauthor_templatethemes\class-megaone-compatibility.php:80
filterarchive_templatethemes\class-megaone-compatibility.php:81
filtercategory_templatethemes\class-megaone-compatibility.php:82
filtertag_templatethemes\class-megaone-compatibility.php:83
filterhome_templatethemes\class-megaone-compatibility.php:84
actiontemplate_redirectthemes\class-megaone-compatibility.php:87
actiontemplate_includethemes\class-megaone-compatibility.php:88
actionwpthemes\class-oceanwp-compatibility.php:27
filtersingle_templatethemes\class-oceanwp-compatibility.php:39
actionocean_headerthemes\class-oceanwp-compatibility.php:47
actionocean_footerthemes\class-oceanwp-compatibility.php:53
filterpage_templatethemes\class-oceanwp-compatibility.php:58
filtersingle_templatethemes\class-oceanwp-compatibility.php:59
filter404_templatethemes\class-oceanwp-compatibility.php:60
filterfrontpage_templatethemes\class-oceanwp-compatibility.php:61
actiontemplate_redirectthemes\class-oceanwp-compatibility.php:64
actiontemplate_includethemes\class-oceanwp-compatibility.php:65
filtersearch_templatethemes\class-oceanwp-compatibility.php:71
filterdate_templatethemes\class-oceanwp-compatibility.php:72
filterauthor_templatethemes\class-oceanwp-compatibility.php:73
filterarchive_templatethemes\class-oceanwp-compatibility.php:74
filtercategory_templatethemes\class-oceanwp-compatibility.php:75
filtertag_templatethemes\class-oceanwp-compatibility.php:76
filterhome_templatethemes\class-oceanwp-compatibility.php:77
actiontemplate_redirectthemes\class-oceanwp-compatibility.php:80
actiontemplate_includethemes\class-oceanwp-compatibility.php:81
actionwpthemes\class-xpro-compatibility.php:27
filtersingle_templatethemes\class-xpro-compatibility.php:39
actionxpro_headerthemes\class-xpro-compatibility.php:48
actionxpro_footerthemes\class-xpro-compatibility.php:53
filterpage_templatethemes\class-xpro-compatibility.php:61
filtersingle_templatethemes\class-xpro-compatibility.php:62
filter404_templatethemes\class-xpro-compatibility.php:63
filterfrontpage_templatethemes\class-xpro-compatibility.php:64
actiontemplate_redirectthemes\class-xpro-compatibility.php:67
actiontemplate_includethemes\class-xpro-compatibility.php:68
filtersearch_templatethemes\class-xpro-compatibility.php:78
filterdate_templatethemes\class-xpro-compatibility.php:79
filterauthor_templatethemes\class-xpro-compatibility.php:80
filterarchive_templatethemes\class-xpro-compatibility.php:81
filtercategory_templatethemes\class-xpro-compatibility.php:82
filtertag_templatethemes\class-xpro-compatibility.php:83
filterhome_templatethemes\class-xpro-compatibility.php:84
actiontemplate_redirectthemes\class-xpro-compatibility.php:87
actiontemplate_includethemes\class-xpro-compatibility.php:88
actioninitxpro-theme-builder.php:34
actionplugins_loadedxpro-theme-builder.php:37
actionadmin_noticesxpro-theme-builder.php:77
Maintenance & Trust

Xpro Theme Builder For Elementor – FREE Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 4, 2025
PHP min version7.0
Downloads120K

Community Trust

Rating100/100
Number of ratings14
Active installs10K
Developer Profile

Xpro Theme Builder For Elementor – FREE Developer Profile

Xpro

7 plugins · 42K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
19 days
View full developer profile
Detection Fingerprints

How We Detect Xpro Theme Builder For Elementor – FREE

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/xpro-theme-builder/assets/css/xpro-theme-builder-public.css/wp-content/plugins/xpro-theme-builder/assets/js/xpro-theme-builder-public.js/wp-content/plugins/xpro-theme-builder/assets/css/xpro-theme-builder-editor.css/wp-content/plugins/xpro-theme-builder/assets/js/xpro-theme-builder-editor.js
Script Paths
/wp-content/plugins/xpro-theme-builder/assets/js/xpro-theme-builder-public.js/wp-content/plugins/xpro-theme-builder/assets/js/xpro-theme-builder-editor.js
Version Parameters
xpro-theme-builder/assets/css/xpro-theme-builder-public.css?ver=xpro-theme-builder/assets/js/xpro-theme-builder-public.js?ver=xpro-theme-builder/assets/css/xpro-theme-builder-editor.css?ver=xpro-theme-builder/assets/js/xpro-theme-builder-editor.js?ver=

HTML / DOM Fingerprints

CSS Classes
xpro-theme-builder-template-wrapper
Data Attributes
data-xpro-template-id
JS Globals
XproThemeBuilder
REST Endpoints
/wp-json/xpro-theme-builder/v1/get-template-content
Shortcode Output
[xpro_theme_builder_template[xpro_comments_template
FAQ

Frequently Asked Questions about Xpro Theme Builder For Elementor – FREE