aThemes Addons for Elementor Security & Risk Analysis

wordpress.org/plugins/athemes-addons-for-elementor-lite

A collection of 30+ essential Elementor addons that let you create galleries, sliders, calls to action, forms, pricing tables, animations, and more.

8K active installs v1.1.8 PHP 5.6+ WP 5.5+ Updated Mar 5, 2026
addonsathemeselementorextensionswidgets
92
A · Safe
CVEs total7
Unpatched0
Last CVENov 7, 2025
Safety Verdict

Is aThemes Addons for Elementor Safe to Use in 2026?

Generally Safe

Score 92/100

aThemes Addons for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

7 known CVEsLast CVE: Nov 7, 2025Updated 29d ago
Risk Assessment

The plugin "athemes-addons-for-elementor-lite" v1.1.8 exhibits a mixed security posture. While it demonstrates good practices like a high percentage of prepared SQL statements and properly escaped output, significant concerns exist. The presence of one AJAX handler without authentication checks represents a direct entry point for potential unauthorized actions. Additionally, the taint analysis reveals one flow with unsanitized paths, indicating a potential for vulnerabilities if this flow is exploited.

The vulnerability history is a substantial red flag. With a total of 7 known CVEs, including one high-severity and six medium-severity vulnerabilities in the past, this plugin has a documented track record of security flaws. The historical prevalence of 'PHP Remote File Inclusion' and 'Cross-site Scripting' vulnerabilities suggests recurring weaknesses in input handling and file inclusion mechanisms. Although currently no unpatched CVEs are listed, the past history necessitates extreme caution.

In conclusion, while the current static analysis shows some positive indicators regarding secure coding practices, the significant number of past vulnerabilities and the identified unprotected AJAX handler and unsanitized path flow present notable risks. Users should be aware of the plugin's history and the potential for undiscovered or reintroduced vulnerabilities.

Key Concerns

  • AJAX handler without authentication checks
  • Flow with unsanitized paths
  • History of 1 High severity CVE
  • History of 6 Medium severity CVEs
Vulnerabilities
7

aThemes Addons for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
6 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
6

7 total CVEs

CVE-2025-12837medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

aThemes Addons for Elementor <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Call To Action Widget

Nov 7, 2025 Patched in 1.1.6 (1d)
CVE-2025-60112medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

aThemes Addons for Elementor <= 1.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 26, 2025 Patched in 1.1.3 (28d)
CVE-2025-8149medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

aThemes Addons for Elementor Lite <= 1.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

Sep 5, 2025 Patched in 1.1.3 (1d)
CVE-2025-32158high · 8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

aThemes Addons for Elementor <= 1.1.3 - Authenticated (Contributor+) Local File Inclusion

Apr 4, 2025 Patched in 1.1.4 (188d)
CVE-2025-22646medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

aThemes Addons for Elementor <= 1.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

Feb 3, 2025 Patched in 1.0.9 (10d)
CVE-2024-13547medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

aThemes Addons for Elementor <= 1.0.12 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 31, 2025 Patched in 1.0.13 (1d)
CVE-2024-51675medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

aThemes Addons for Elementor <= 1.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 1, 2024 Patched in 1.0.8 (6d)
Code Analysis
Analyzed Mar 16, 2026

aThemes Addons for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
4 prepared
Unescaped Output
100
928 escaped
Nonce Checks
20
Capability Checks
22
File Operations
1
External Requests
8
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

80% prepared5 total queries

Output Escaping

90% escaped1028 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

8 flows1 with unsanitized paths
footer_internal_scripts (admin\classes\class-athemes-addons-admin-menu.php:277)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

aThemes Addons for Elementor Attack Surface

Entry Points20
Unprotected1

AJAX Handlers 20

authwp_ajax_athemes_addons_notifications_readadmin\classes\class-athemes-addons-admin-menu.php:64
authwp_ajax_aafe_save_settingsadmin\classes\class-athemes-addons-admin-settings.php:34
authwp_ajax_addons_install_pluginadmin\classes\class-athemes-addons-plugin-installer.php:42
authwp_ajax_addons_install_external_pluginadmin\classes\class-athemes-addons-plugin-installer.php:43
authwp_ajax_aafe_mailchimp_subscribeinc\classes\class-athemes-addons-ajax-callbacks.php:21
noprivwp_ajax_aafe_mailchimp_subscribeinc\classes\class-athemes-addons-ajax-callbacks.php:22
authwp_ajax_aafe_product_filterinc\classes\class-athemes-addons-ajax-callbacks.php:25
noprivwp_ajax_aafe_product_filterinc\classes\class-athemes-addons-ajax-callbacks.php:26
authwp_ajax_aafe_posts_filter_autocompleteinc\classes\class-athemes-addons-ajax-callbacks.php:29
authwp_ajax_aafe_get_posts_value_titlesinc\classes\class-athemes-addons-ajax-callbacks.php:30
authwp_ajax_athemes_addons_module_activateinc\classes\class-athemes-addons-modules.php:43
authwp_ajax_athemes_addons_module_deactivateinc\classes\class-athemes-addons-modules.php:44
authwp_ajax_athemes_addons_module_feedbackinc\classes\class-athemes-addons-modules.php:45
authwp_ajax_athemes_addons_update_posts_filterinc\classes\class-athemes-addons-posts-helper.php:40
authwp_ajax_athemes_addons_update_template_conditionsinc\theme-builder\class-athemes-addons-theme-builder-admin.php:41
authwp_ajax_athemes_addons_delete_templateinc\theme-builder\class-athemes-addons-theme-builder-admin.php:42
authwp_ajax_athemes_addons_header_typeinc\theme-builder\class-athemes-addons-theme-builder-admin.php:43
authwp_ajax_athemes_addons_create_templateinc\theme-builder\class-athemes-addons-theme-builder-admin.php:44
authwp_ajax_athemes_addons_get_templatesinc\theme-builder\class-athemes-addons-theme-builder-admin.php:45
authwp_ajax_athemes_addons_templates_display_conditions_select_ajaxinc\theme-builder\display-conditions\ajax-callback.php:257
WordPress Hooks 132
actioninitadmin\class-athemes-addons-admin-loader.php:35
actionadmin_enqueue_scriptsadmin\class-athemes-addons-admin-loader.php:37
filteradmin_footer_textadmin\class-athemes-addons-admin-loader.php:39
filteradmin_body_classadmin\class-athemes-addons-admin-loader.php:40
actionadmin_enqueue_scriptsadmin\classes\class-athemes-addons-admin-menu.php:60
actionadmin_menuadmin\classes\class-athemes-addons-admin-menu.php:63
actionadmin_footeradmin\classes\class-athemes-addons-admin-menu.php:66
actionadmin_noticesadmin\classes\class-athemes-addons-admin-notices.php:34
actionadmin_initadmin\classes\class-athemes-addons-plugin-installer.php:24
actionadmin_enqueue_scriptsadmin\classes\class-athemes-addons-plugin-installer.php:41
actionadmin_initadmin\classes\class-athemes-addons-review-notice.php:20
actionadmin_noticesadmin\classes\class-athemes-addons-review-notice.php:21
actionadmin_initadmin\classes\class-athemes-addons-review-notice.php:22
actionadmin_initadmin\classes\class-athemes-addons-review-notice.php:23
actionplugins_loadedinc\class-athemes-addons-loader.php:54
actionelementor/elements/categories_registeredinc\class-athemes-addons-loader.php:57
actionelementor/widgets/registerinc\class-athemes-addons-loader.php:60
actionelementor/initinc\class-athemes-addons-loader.php:63
actionelementor/initinc\class-athemes-addons-loader.php:66
actionelementor/initinc\class-athemes-addons-loader.php:69
actionwp_enqueue_scriptsinc\class-athemes-addons-loader.php:72
actionelementor/editor/before_enqueue_scriptsinc\class-athemes-addons-loader.php:75
actionelementor/editor/after_enqueue_scriptsinc\class-athemes-addons-loader.php:78
filterbody_classinc\class-athemes-addons-loader.php:81
actionwp_footerinc\class-athemes-addons-loader.php:84
actionelementor/editor/after_saveinc\class-athemes-addons-loader.php:87
actionelementor/controls/controls_registeredinc\class-athemes-addons-loader.php:90
actionpre_get_postsinc\classes\class-athemes-addons-posts-helper.php:38
filterfound_postsinc\classes\class-athemes-addons-posts-helper.php:39
filtermerchant_product_swatch_shop_catalog_add_to_cart_button_htmlinc\functions.php:1315
actionelementor/editor/footerinc\library\library-manager.php:15
actionelementor/ajax/register_actionsinc\library\library-manager.php:16
actionelementor/preview/enqueue_stylesinc\library\library-manager.php:17
actionelementor/editor/after_enqueue_scriptsinc\library\library-manager.php:18
filterathemes_addons_modulesinc\modules\class-add-module.php:51
filterathemes_addons_module_file_pathinc\modules\class-add-module.php:54
filteradmin_body_classinc\modules\class-add-module.php:57
actionelementor/element/after_section_endinc\modules\extensions\custom-css\class-custom-css.php:32
actionelementor/element/parse_cssinc\modules\extensions\custom-css\class-custom-css.php:34
actionelementor/element/after_section_endinc\modules\extensions\custom-css\class-custom-css.php:36
actionelementor/documents/register_controlsinc\modules\extensions\custom-js\class-custom-js.php:31
actionadmin_action_aafe_duplicateinc\modules\extensions\page-duplicator\class-page-duplicator.php:27
filterpage_row_actionsinc\modules\extensions\page-duplicator\class-page-duplicator.php:28
filterpost_row_actionsinc\modules\extensions\page-duplicator\class-page-duplicator.php:29
actionelementor/preview/enqueue_scriptsinc\modules\extensions\parallax\class-parallax.php:37
actionelementor/preview/enqueue_scriptsinc\modules\extensions\parallax\class-parallax.php:38
actionelementor/element/section/section_advanced/after_section_endinc\modules\extensions\parallax\class-parallax.php:41
actionelementor/element/container/section_layout/after_section_endinc\modules\extensions\parallax\class-parallax.php:42
actionelementor/frontend/section/before_renderinc\modules\extensions\parallax\class-parallax.php:45
actionelementor/frontend/container/before_renderinc\modules\extensions\parallax\class-parallax.php:46
actionelementor/frontend/section/before_renderinc\modules\extensions\parallax\class-parallax.php:49
actionelementor/frontend/container/before_renderinc\modules\extensions\parallax\class-parallax.php:50
actionelementor/frontend/section/before_renderinc\modules\extensions\parallax\class-parallax.php:53
actionelementor/frontend/container/before_renderinc\modules\extensions\parallax\class-parallax.php:54
actionelementor/frontend/section/after_renderinc\modules\extensions\parallax\class-parallax.php:57
actionelementor/frontend/container/after_renderinc\modules\extensions\parallax\class-parallax.php:58
actionelementor/container/print_templateinc\modules\extensions\parallax\class-parallax.php:60
actionelementor/section/print_templateinc\modules\extensions\parallax\class-parallax.php:61
actionelementor/widget/athemes-addons-call-to-action/skins_initinc\modules\widgets\call-to-action\skins\class-call-to-action-banner.php:115
actionelementor/widget/athemes-addons-gallery/skins_initinc\modules\widgets\gallery\skins\class-gallery-card.php:209
actionelementor/element/athemes-addons-posts-carousel/section_style_card/after_section_endinc\modules\widgets\posts-carousel\skins\class-posts-carousel-banner.php:34
actionelementor/element/athemes-addons-posts-carousel/section_item_settings/after_section_endinc\modules\widgets\posts-carousel\skins\class-posts-carousel-banner.php:35
actionelementor/widget/athemes-addons-posts-carousel/skins_initinc\modules\widgets\posts-carousel\skins\class-posts-carousel-banner.php:262
actionelementor/element/athemes-addons-posts-carousel/section_style_image/after_section_endinc\modules\widgets\posts-carousel\skins\class-posts-carousel-modern.php:34
actionelementor/element/athemes-addons-posts-carousel/section_style_meta/after_section_endinc\modules\widgets\posts-carousel\skins\class-posts-carousel-modern.php:35
actionelementor/widget/athemes-addons-posts-carousel/skins_initinc\modules\widgets\posts-carousel\skins\class-posts-carousel-modern.php:244
actionelementor/element/athemes-addons-posts-list/section_style_card/after_section_endinc\modules\widgets\posts-list\skins\class-posts-list-banner.php:34
actionelementor/element/athemes-addons-posts-list/section_item_settings/after_section_endinc\modules\widgets\posts-list\skins\class-posts-list-banner.php:35
actionelementor/widget/athemes-addons-posts-list/skins_initinc\modules\widgets\posts-list\skins\class-posts-list-banner.php:288
actionelementor/element/athemes-addons-posts-list/section_style_image/after_section_endinc\modules\widgets\posts-list\skins\class-posts-list-modern.php:34
actionelementor/element/athemes-addons-posts-list/section_style_meta/after_section_endinc\modules\widgets\posts-list\skins\class-posts-list-modern.php:35
actionelementor/widget/athemes-addons-posts-list/skins_initinc\modules\widgets\posts-list\skins\class-posts-list-modern.php:275
actionelementor/element/athemes-addons-posts-list/section_style_titles/after_section_endinc\modules\widgets\posts-list\skins\class-posts-list-title-list.php:34
actionelementor/widget/athemes-addons-posts-list/skins_initinc\modules\widgets\posts-list\skins\class-posts-list-title-list.php:227
actionelementor/widget/athemes-addons-testimonials/skins_initinc\modules\widgets\testimonials\skins\class-testimonials-centered.php:165
actionelementor/widget/athemes-addons-testimonials/skins_initinc\modules\widgets\testimonials\skins\class-testimonials-modern.php:167
actionelementor/widget/athemes-addons-testimonials/skins_initinc\modules\widgets\testimonials\skins\class-testimonials-side-by-side.php:167
filterwoocommerce_loop_add_to_cart_linkinc\modules\widgets\woo-product-grid\templates\product-template-style2.php:63
filterwoocommerce_loop_add_to_cart_linkinc\modules\widgets\woo-product-grid\templates\product-template-style4.php:68
actionadmin_footerinc\theme-builder\class-athemes-addons-theme-builder-admin.php:35
actioninitinc\theme-builder\class-athemes-addons-theme-builder-admin.php:38
actioninitinc\theme-builder\class-athemes-addons-theme-builder-cpt.php:34
actionadd_meta_boxesinc\theme-builder\class-athemes-addons-theme-builder-metabox.php:35
actionsave_postinc\theme-builder\class-athemes-addons-theme-builder-metabox.php:36
actionsave_postinc\theme-builder\class-athemes-addons-theme-builder-metabox.php:37
actionwp_enqueue_scriptsinc\theme-builder\class-athemes-addons-theme-builder.php:44
actioninitinc\theme-builder\class-athemes-addons-theme-builder.php:47
actionwpinc\theme-builder\class-athemes-addons-theme-builder.php:52
actionwpinc\theme-builder\class-athemes-addons-theme-builder.php:53
actionwpinc\theme-builder\class-athemes-addons-theme-builder.php:54
actionwpinc\theme-builder\class-athemes-addons-theme-builder.php:56
actionwpinc\theme-builder\class-athemes-addons-theme-builder.php:57
actionwp_footerinc\theme-builder\class-athemes-addons-theme-builder.php:58
actionget_headerinc\theme-builder\class-athemes-addons-theme-builder.php:60
actionget_footerinc\theme-builder\class-athemes-addons-theme-builder.php:61
actionathemes_addons_do_headerinc\theme-builder\class-athemes-addons-theme-builder.php:62
actionathemes_addons_do_footerinc\theme-builder\class-athemes-addons-theme-builder.php:63
actionwpinc\theme-builder\class-athemes-addons-theme-builder.php:68
actionwpinc\theme-builder\class-athemes-addons-theme-builder.php:71
actionwpinc\theme-builder\class-athemes-addons-theme-builder.php:74
actionwpinc\theme-builder\class-athemes-addons-theme-builder.php:77
actionplugins_loadedinc\theme-builder\class-athemes-addons-theme-builder.php:80
actionsingle_templateinc\theme-builder\class-athemes-addons-theme-builder.php:83
actiontemplate_redirectinc\theme-builder\class-athemes-addons-theme-builder.php:86
actionwp_headinc\theme-builder\class-athemes-addons-theme-builder.php:89
actionathemes_addons_do_contentinc\theme-builder\class-athemes-addons-theme-builder.php:284
actionathemes_addons_do_contentinc\theme-builder\class-athemes-addons-theme-builder.php:305
actiontemplate_includeinc\theme-builder\class-athemes-addons-theme-builder.php:319
actionathemes_addons_do_contentinc\theme-builder\class-athemes-addons-theme-builder.php:322
actiontemplate_includeinc\theme-builder\class-athemes-addons-theme-builder.php:335
actionathemes_addons_do_contentinc\theme-builder\class-athemes-addons-theme-builder.php:338
actionastra_headerinc\theme-builder\compatibility\class-astra-theme-builder-compatibility.php:48
actionastra_footerinc\theme-builder\compatibility\class-astra-theme-builder-compatibility.php:65
filterblocksy:builder:header:enabledinc\theme-builder\compatibility\class-blocksy-theme-builder-compatibility.php:37
actionblocksy:header:beforeinc\theme-builder\compatibility\class-blocksy-theme-builder-compatibility.php:40
filterblocksy:builder:footer:enabledinc\theme-builder\compatibility\class-blocksy-theme-builder-compatibility.php:50
actionblocksy:builder:footer:enabledinc\theme-builder\compatibility\class-blocksy-theme-builder-compatibility.php:53
actionbotiga_headerinc\theme-builder\compatibility\class-botiga-theme-builder-compatibility.php:44
actionbotiga_footerinc\theme-builder\compatibility\class-botiga-theme-builder-compatibility.php:57
actiongenerate_headerinc\theme-builder\compatibility\class-generatepress-theme-builder-compatibility.php:44
actiongenerate_footerinc\theme-builder\compatibility\class-generatepress-theme-builder-compatibility.php:58
actionkadence_headerinc\theme-builder\compatibility\class-kadence-theme-builder-compatibility.php:45
actionkadence_footerinc\theme-builder\compatibility\class-kadence-theme-builder-compatibility.php:58
actionneve_do_headerinc\theme-builder\compatibility\class-neve-theme-builder-compatibility.php:45
actionneve_do_footerinc\theme-builder\compatibility\class-neve-theme-builder-compatibility.php:58
actionocean_headerinc\theme-builder\compatibility\class-oceanwp-theme-builder-compatibility.php:46
actionocean_footerinc\theme-builder\compatibility\class-oceanwp-theme-builder-compatibility.php:59
actionsydney_headerinc\theme-builder\compatibility\class-sydney-theme-builder-compatibility.php:44
actionwp_enqueue_scriptsinc\theme-builder\compatibility\class-sydney-theme-builder-compatibility.php:57
actionsydney_before_footerinc\theme-builder\compatibility\class-sydney-theme-builder-compatibility.php:62
actionupdate_option_athemes-addons-settingsinc\usage-tracking\class-athemes-addons-usage-tracking.php:47
actioninitinc\usage-tracking\class-athemes-addons-usage-tracking.php:416
Maintenance & Trust

aThemes Addons for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 5, 2026
PHP min version5.6
Downloads93K

Community Trust

Rating100/100
Number of ratings3
Active installs8K
Developer Profile

aThemes Addons for Elementor Developer Profile

Syed Balkhi

94 plugins · 23.5M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
795 days
View full developer profile
Detection Fingerprints

How We Detect aThemes Addons for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/athemes-addons-for-elementor-lite/assets/css/admin/admin.min.css/wp-content/plugins/athemes-addons-for-elementor-lite/assets/js/admin/admin.min.js/wp-content/plugins/athemes-addons-for-elementor-lite/assets/js/vendor/select2.min.js/wp-content/plugins/athemes-addons-for-elementor-lite/assets/css/admin/select2.min.css
Script Paths
/wp-content/plugins/athemes-addons-for-elementor-lite/assets/js/admin/admin.min.js/wp-content/plugins/athemes-addons-for-elementor-lite/assets/js/vendor/select2.min.js
Version Parameters
/wp-content/plugins/athemes-addons-for-elementor-lite/assets/css/admin/admin.min.css?ver=/wp-content/plugins/athemes-addons-for-elementor-lite/assets/js/admin/admin.min.js?ver=/wp-content/plugins/athemes-addons-for-elementor-lite/assets/js/vendor/select2.min.js?ver=/wp-content/plugins/athemes-addons-for-elementor-lite/assets/css/admin/select2.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
athemes-addons-admin-footer-text-link
JS Globals
athemes_addons_elementor
FAQ

Frequently Asked Questions about aThemes Addons for Elementor