Astra Widgets Security & Risk Analysis

wordpress.org/plugins/astra-widgets

Quickest solution to add widgets like Address, Social Profiles and List icons on a website built with Astra.

200K active installs v1.2.17 PHP 5.2+ WP 4.7+ Updated Dec 15, 2025
add-widgetaddress-widgetlist-icon-widgetsocial-mediasocial-profile-widget
96
A · Safe
CVEs total3
Unpatched0
Last CVEDec 28, 2025
Safety Verdict

Is Astra Widgets Safe to Use in 2026?

Generally Safe

Score 96/100

Astra Widgets has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Dec 28, 2025Updated 3mo ago
Risk Assessment

The 'astra-widgets' plugin v1.2.17 exhibits a mixed security posture. On the positive side, the static analysis reveals no identified critical or high-severity taint flows, a very high percentage of properly escaped output, and the use of prepared statements for all SQL queries. The plugin also demonstrates good practices with nonce checks and capability checks, and a limited attack surface in terms of entry points. However, a concerning aspect is the history of three medium-severity vulnerabilities, all related to Cross-Site Scripting (XSS). This pattern suggests a recurring weakness in handling user input that could potentially lead to future exploitable flaws if not addressed rigorously. Despite the current absence of unpatched CVEs and a generally clean static analysis, the past vulnerability history warrants caution.

Key Concerns

  • Past medium severity XSS vulnerabilities
Vulnerabilities
3

Astra Widgets Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2025-68497medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Astra Widgets <= 1.2.16 - Authenticated (Editor+) Stored Cross-Site Scripting

Dec 28, 2025 Patched in 1.2.17 (9d)
CVE-2024-56274medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Astra Widgets <= 1.2.15 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 3, 2025 Patched in 1.2.16 (6d)
CVE-2024-50439medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Astra Widgets <= 1.2.14 - Authenticated (Contributor+) Stored Cross-Site Scripting

Oct 24, 2024 Patched in 1.2.15 (7d)
Code Analysis
Analyzed Mar 16, 2026

Astra Widgets Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
258 escaped
Nonce Checks
1
Capability Checks
2
File Operations
2
External Requests
1
Bundled Libraries
0

Output Escaping

96% escaped269 total outputs
Attack Surface

Astra Widgets Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actioninitadmin\bsf-analytics\class-bsf-analytics-loader.php:68
actionadmin_initadmin\bsf-analytics\class-bsf-analytics.php:55
actionadmin_noticesadmin\bsf-analytics\class-bsf-analytics.php:56
actioninitadmin\bsf-analytics\class-bsf-analytics.php:57
actionadmin_initadmin\bsf-analytics\class-bsf-analytics.php:61
actionadmin_enqueue_scriptsclasses\class-astra-widgets-helper.php:57
filtercustomize_save_responseclasses\class-astra-widgets-helper.php:58
actionwidgets_initclasses\class-astra-widgets-loader.php:48
actionwp_enqueue_scriptsclasses\class-astra-widgets-loader.php:49
actionadmin_enqueue_scriptsclasses\class-astra-widgets-loader.php:50
actionwp_enqueue_scriptsclasses\widgets\class-astra-widget-address.php:69
actionwp_enqueue_scriptsclasses\widgets\class-astra-widget-list-icons.php:80
actionadmin_enqueue_scriptsclasses\widgets\class-astra-widget-list-icons.php:81
actionwp_enqueue_scriptsclasses\widgets\class-astra-widget-social-profiles.php:80
actionadmin_enqueue_scriptsclasses\widgets\class-astra-widget-social-profiles.php:81
Maintenance & Trust

Astra Widgets Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 15, 2025
PHP min version5.2
Downloads4.5M

Community Trust

Rating78/100
Number of ratings17
Active installs200K
Developer Profile

Astra Widgets Developer Profile

Brainstorm Force

32 plugins · 8.6M total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
196 days
View full developer profile
Detection Fingerprints

How We Detect Astra Widgets

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/astra-widgets/admin/bsf-analytics/assets/css/minified/style.min.css
Version Parameters
astra-widgets/admin/bsf-analytics/assets/css/minified/style.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
astra-noticesastra-notices-containernotice-contentnotice-heading
Data Attributes
data-repeat-notice-after
REST Endpoints
/wp-json/bsf-core/v1/analytics/
FAQ

Frequently Asked Questions about Astra Widgets