AddonNest for Elementor Security & Risk Analysis

wordpress.org/plugins/addonnest

Supercharge Elementor with 20+ premium-quality widgets for stunning websites. No coding needed!

0 active installs v1.0.2 PHP 7.4+ WP 5.9+ Updated May 16, 2025
dynamic-contentelementorelementor-widgetsfree-widgetspage-builder
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AddonNest for Elementor Safe to Use in 2026?

Generally Safe

Score 100/100

AddonNest for Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The 'addonnest' plugin version 1.0.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices in handling SQL queries, utilizing prepared statements exclusively. Furthermore, the vast majority of its output is properly escaped, and it avoids risky operations like raw file manipulation or external HTTP requests. Its vulnerability history is also clean, with no known CVEs, which suggests a generally stable and well-maintained codebase.

However, a significant concern arises from the presence of one unprotected AJAX handler. This represents a direct entry point into the plugin's functionality that is not secured with any authentication or capability checks. While the static analysis and taint analysis did not reveal any critical or high-severity code signals like dangerous functions or unsanitized paths, the unprotected AJAX handler alone is a critical flaw that could be exploited to perform unauthorized actions. The absence of nonce checks on this handler further exacerbates this risk.

In conclusion, while the plugin has a commendable track record and adheres to several security best practices, the single unprotected AJAX handler poses a substantial security risk. This weakness needs immediate attention to prevent potential exploitation. The lack of nonce checks on this handler is a direct omission that attackers could leverage. Strengthening this specific entry point is paramount to improving the plugin's overall security.

Key Concerns

  • Unprotected AJAX handler
  • Missing nonce checks on AJAX
Vulnerabilities
None known

AddonNest for Elementor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AddonNest for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
14
301 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

96% escaped315 total outputs
Attack Surface
1 unprotected

AddonNest for Elementor Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_addonnest_settings_resetincludes\elementor\AddonNest_Base.php:34
WordPress Hooks 10
actionadmin_initincludes\AddonNest.php:18
actionadmin_noticesincludes\AddonNest.php:34
actionwp_enqueue_scriptsincludes\elementor\AddonNest_Base.php:31
actioninitincludes\elementor\AddonNest_Base.php:32
actionadmin_headincludes\elementor\AddonNest_Base.php:33
filteradmin_footer_textincludes\elementor\AddonNest_Base.php:35
actionpre_get_postsincludes\elementor\AddonNest_Base.php:42
filtermce_buttonsincludes\elementor\AddonNest_Base.php:70
actionelementor/initincludes\elementor\elementor-core.php:14
actionelementor/widgets/widgets_registeredincludes\elementor\elementor-core.php:37
Maintenance & Trust

AddonNest for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 16, 2025
PHP min version7.4
Downloads481

Community Trust

Rating100/100
Number of ratings2
Active installs0
Developer Profile

AddonNest for Elementor Developer Profile

TheBitCraft

3 plugins · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AddonNest for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/addonnest/assets/src/library/css/slick.css/wp-content/plugins/addonnest/assets/dist/css/addonnest-front.css/wp-content/plugins/addonnest/assets/src/css/jquery-ui.css/wp-content/plugins/addonnest/assets/src/library/js/slick.min.js/wp-content/plugins/addonnest/assets/src/library/js/slick-animation.min.js/wp-content/plugins/addonnest/assets/src/js/addonnest-front.js
Script Paths
/wp-content/plugins/addonnest/assets/src/library/js/slick.min.js/wp-content/plugins/addonnest/assets/src/library/js/slick-animation.min.js/wp-content/plugins/addonnest/assets/src/js/addonnest-front.js
Version Parameters
ver=1.0.2

HTML / DOM Fingerprints

CSS Classes
addonnest-blog-list
JS Globals
AddonNest_Elementor
FAQ

Frequently Asked Questions about AddonNest for Elementor