Astro Elementor Widgets Lite Security & Risk Analysis

wordpress.org/plugins/astro-elementor-widgets-lite

A collection of dynamic content widgets for Elementor.

10 active installs v1.0.1 PHP 7.0+ WP 4.7+ Updated Sep 20, 2020
addonsastroelementorelementor-addonselementor-elements
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Astro Elementor Widgets Lite Safe to Use in 2026?

Generally Safe

Score 85/100

Astro Elementor Widgets Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of "astro-elementor-widgets-lite" v1.0.1 reveals a plugin with a seemingly low attack surface. It reports zero AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, all identified SQL queries use prepared statements. This suggests adherence to some good security practices, particularly regarding data sanitization for database operations. However, a significant concern arises from the output escaping. With 32 total outputs and only 25% properly escaped, there is a high probability of cross-site scripting (XSS) vulnerabilities being present in the plugin. The lack of reported dangerous functions, file operations, external HTTP requests, nonce checks, and capability checks, while positive, doesn't fully offset the output escaping weakness.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive indicator, suggesting that the plugin has either been well-developed and maintained or has not yet been a target for widespread vulnerability discovery. However, the absence of past vulnerabilities does not guarantee future security, especially given the identified output escaping issues.

In conclusion, while the plugin demonstrates strengths in database security and a low direct attack surface, the poor output escaping practices represent a critical security weakness that could expose users to XSS attacks. The clean vulnerability history is encouraging but should not lead to complacency, given the identified code quality issues.

Key Concerns

  • Low output escaping (25% properly escaped)
Vulnerabilities
None known

Astro Elementor Widgets Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Astro Elementor Widgets Lite Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Astro Elementor Widgets Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

25% escaped32 total outputs
Attack Surface

Astro Elementor Widgets Lite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionwp_enqueue_scriptsastro-elementor-widgets-lite.php:56
actioninitastro-elementor-widgets-lite.php:57
actionplugins_loadedastro-elementor-widgets-lite.php:58
actionadmin_noticesastro-elementor-widgets-lite.php:113
actionadmin_noticesastro-elementor-widgets-lite.php:118
actionadmin_noticesastro-elementor-widgets-lite.php:123
actionelementor/initastro-elementor-widgets-lite.php:127
actionelementor/widgets/widgets_registeredastro-elementor-widgets-lite.php:128
Maintenance & Trust

Astro Elementor Widgets Lite Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedSep 20, 2020
PHP min version7.0
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Astro Elementor Widgets Lite Developer Profile

MD. Rabiul Islam Robi

3 plugins · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Astro Elementor Widgets Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/astro-elementor-widgets-lite/assets/dist/css/public.min.css/wp-content/plugins/astro-elementor-widgets-lite/assets/dist/js/public.min.js
Script Paths
/wp-content/plugins/astro-elementor-widgets-lite/assets/dist/js/public.min.js
Version Parameters
astro-elementor-widgets-lite/assets/dist/css/public.min.css?ver=astro-elementor-widgets-lite/assets/dist/js/public.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
aewlite-styleaewlite-script
FAQ

Frequently Asked Questions about Astro Elementor Widgets Lite