Dynific Addons for Elementor (formerly AnyWhere Elementor) Security & Risk Analysis

wordpress.org/plugins/anywhere-elementor

Insert Elementor created content anywhere using shortcode. Insert Elementor created content anywhere using shortcode.

80K active installs v1.2.14 PHP + WP 5.0+ Updated Dec 11, 2025
elementorelementor-addonpage-builder
98
A · Safe
CVEs total2
Unpatched0
Last CVEDec 4, 2024
Safety Verdict

Is Dynific Addons for Elementor (formerly AnyWhere Elementor) Safe to Use in 2026?

Generally Safe

Score 98/100

Dynific Addons for Elementor (formerly AnyWhere Elementor) has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Dec 4, 2024Updated 3mo ago
Risk Assessment

The 'anywhere-elementor' plugin version 1.2.14 exhibits a generally good security posture based on the static analysis, with no identified dangerous functions, exclusively prepared SQL statements, and a high percentage of properly escaped outputs. The attack surface is minimal, with only one shortcode, and importantly, no unprotected entry points were detected. Taint analysis also shows no critical or high severity vulnerabilities, indicating the code likely handles user input safely in this regard.

However, the plugin's vulnerability history is a significant concern. With two known CVEs, including a high and a medium severity vulnerability, and a recent history of sensitive information exposure and authorization bypass, there's a clear pattern of past security weaknesses. While there are currently no unpatched CVEs for this specific version, the recurring nature of these issues suggests potential underlying architectural flaws or a less rigorous security review process. The absence of nonce checks across its entry points, despite having capability checks, could also be a point of potential weakness if a vulnerability were to arise that bypasses capability checks.

In conclusion, while version 1.2.14 benefits from strong static analysis results and a small attack surface, the historical vulnerability data casts a shadow over its overall trustworthiness. Users should be aware of the plugin's past security incidents and ensure they are always running the latest patched version. The lack of nonce checks on the single shortcode warrants attention as a potential future exploit vector.

Key Concerns

  • History of High severity vulnerability
  • History of Medium severity vulnerability
  • No nonce checks on entry points
  • Recent vulnerability (2024-12-04)
Vulnerabilities
2

Dynific Addons for Elementor (formerly AnyWhere Elementor) Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2024-10777medium · 4.3Authorization Bypass Through User-Controlled Key

AnyWhere Elementor <= 1.2.11 - Authenticated (Contributor+) Post Disclosure

Dec 4, 2024 Patched in 1.2.12 (1d)
CVE-2023-0443high · 8.6Exposure of Sensitive Information to an Unauthorized Actor

AnyWhere Elementor <= 1.2.7 - Sensitive Information Exposure

May 2, 2023 Patched in 1.2.8 (266d)
Code Analysis
Analyzed Mar 16, 2026

Dynific Addons for Elementor (formerly AnyWhere Elementor) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
22 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

85% escaped26 total outputs
Attack Surface

Dynific Addons for Elementor (formerly AnyWhere Elementor) Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[INSERT_ELEMENTOR] includes\shortcode.php:21
WordPress Hooks 11
actionplugins_loadedincludes\bootstrap.php:19
actionwp_headincludes\bootstrap.php:21
filtertemplate_redirectincludes\bootstrap.php:23
actionadmin_enqueue_scriptsincludes\bootstrap.php:25
actionadd_meta_boxesincludes\meta-box.php:19
filtermanage_ae_global_templates_posts_columnsincludes\meta-box.php:21
actionmanage_ae_global_templates_posts_custom_columnincludes\meta-box.php:22
actioninitincludes\post-type.php:19
actionelementor/initincludes\post-type.php:21
filterwidget_textincludes\shortcode.php:23
actionin_admin_headerincludes\ui.php:19
Maintenance & Trust

Dynific Addons for Elementor (formerly AnyWhere Elementor) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 11, 2025
PHP min version
Downloads1.5M

Community Trust

Rating96/100
Number of ratings104
Active installs80K
Developer Profile

Dynific Addons for Elementor (formerly AnyWhere Elementor) Developer Profile

WPVibes

10 plugins · 201K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
157 days
View full developer profile
Detection Fingerprints

How We Detect Dynific Addons for Elementor (formerly AnyWhere Elementor)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/anywhere-elementor/includes/admin/css/admin.css
Version Parameters
anywhere-elementor/includes/admin/css/admin.css?ver=1.2.14

HTML / DOM Fingerprints

CSS Classes
ae_dataelementor-editor-element-setting
Data Attributes
data-id
Shortcode Output
[INSERT_ELEMENTOR id=do_shortcode('[INSERT_ELEMENTOR id=
FAQ

Frequently Asked Questions about Dynific Addons for Elementor (formerly AnyWhere Elementor)