Directorist AddonsKit for Elementor Security & Risk Analysis

wordpress.org/plugins/addonskit-for-elementor

Enhance your Elementor experience with a variety of stunning templates and advanced widgets to build beautiful directory websites.

10K active installs v1.3.0 PHP 7.4+ WP 6.0+ Updated Nov 27, 2025
addons-kitdirectorydirectory-websiteselementor-widgettemplates
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 1, 2025
Download
Safety Verdict

Is Directorist AddonsKit for Elementor Safe to Use in 2026?

Generally Safe

Score 99/100

Directorist AddonsKit for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 1, 2025Updated 4mo ago
Risk Assessment

The static analysis of addonskit-for-elementor v1.3.0 indicates a generally strong security posture, with excellent adherence to best practices in several key areas. The complete absence of dangerous functions, 100% prepared SQL statements, and near-perfect output escaping (99%) are significant strengths. Furthermore, the plugin demonstrates a commitment to security by implementing nonce checks and exhibiting no critical or high severity taint flows. The limited attack surface, with zero identified unprotected entry points, also contributes positively to its security.

However, there are a couple of areas that warrant attention. The presence of file operations, while not inherently malicious, could represent a potential vector for attacks if not strictly controlled and validated. More importantly, the plugin has a history of known vulnerabilities, including a medium severity Cross-Site Scripting (XSS) flaw. While the most recent vulnerability is in the future (2025-04-01), suggesting this data might be hypothetical or a projection, the past occurrence of XSS is a concern. The fact that there are currently no unpatched vulnerabilities is positive, but the historical pattern necessitates vigilance.

In conclusion, addonskit-for-elementor v1.3.0 exhibits good development practices, particularly concerning data handling and output sanitization. The low attack surface and absence of critical static code flaws are commendable. Nevertheless, the historical presence of XSS vulnerabilities, even if resolved, and the existence of file operations suggest that ongoing security audits and proactive patching are crucial to maintain a secure environment.

Key Concerns

  • File operations detected
  • Past medium severity CVE (XSS)
Vulnerabilities
1

Directorist AddonsKit for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-31857medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Directorist AddonsKit for Elementor <= 1.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 1, 2025 Patched in 1.1.7 (17d)
Code Analysis
Analyzed Mar 16, 2026

Directorist AddonsKit for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
87 escaped
Nonce Checks
1
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped88 total outputs
Attack Surface

Directorist AddonsKit for Elementor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_noticesaddonskit-for-elementor.php:67
actionadmin_noticesaddonskit-for-elementor.php:72
actionplugins_loadedaddonskit-for-elementor.php:215
filterdirectorist_account_page_accessibleapp\DirectoristSupport.php:17
actionelementor/widgets/registerapp\Elements\Elements.php:34
actionelementor/dynamic_tags/registerapp\Elements\Elements.php:35
filterdirectorist_custom_single_listing_pre_page_contentapp\Elements\Elements.php:37
actionwp_admin_scriptsapp\Enqueuer.php:15
actionwp_enqueue_scriptsapp\Enqueuer.php:16
Maintenance & Trust

Directorist AddonsKit for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 27, 2025
PHP min version7.4
Downloads63K

Community Trust

Rating40/100
Number of ratings4
Active installs10K
Developer Profile

Directorist AddonsKit for Elementor Developer Profile

wpWax

15 plugins · 62K total installs

67
trust score
Avg Security Score
83/100
Avg Patch Time
210 days
View full developer profile
Detection Fingerprints

How We Detect Directorist AddonsKit for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/addonskit-for-elementor/assets/css/style-global.css
Version Parameters
addonskit-for-elementor/assets/css/style-global.css?ver=

HTML / DOM Fingerprints

CSS Classes
directorist-viewasdirectorist-viewas__itemdirectorist-dropdowndirectorist-dropdown__toggle
FAQ

Frequently Asked Questions about Directorist AddonsKit for Elementor