BlogKit – Advanced Blog Elements for Elementor Security & Risk Analysis

wordpress.org/plugins/blogkit

BlogKit enhances your WordPress blog with advanced Elementor widgets and features for creating beautiful blog layouts.

10 active installs v1.3.1 PHP 8.0+ WP 5.8+ Updated Unknown
blog-designcustom-post-layoutelementorgrid-posts
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is BlogKit – Advanced Blog Elements for Elementor Safe to Use in 2026?

Generally Safe

Score 100/100

BlogKit – Advanced Blog Elements for Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The blogkit plugin v1.3.1 exhibits a generally strong security posture based on the provided static analysis. The absence of any recorded vulnerabilities (CVEs) and the clean taint analysis results are positive indicators. Furthermore, the plugin demonstrates good coding practices by utilizing prepared statements for all SQL queries and having no file operations or external HTTP requests, significantly reducing common attack vectors. The limited attack surface is also a positive, with no AJAX handlers, REST API routes, shortcodes, or cron events identified.

However, there are some areas for improvement. The output escaping is only 68% proper, which, while not critical given the lack of identified flows or attack surface, still presents a potential for cross-site scripting (XSS) vulnerabilities if malicious input were to reach these unescaped outputs. The complete lack of nonce checks and capability checks, particularly in conjunction with a potentially larger, albeit currently unexposed, attack surface, represents a notable concern. While there are no direct entry points identified as unprotected, the absence of these fundamental security mechanisms leaves the plugin vulnerable should an attack vector be discovered or introduced in future updates.

In conclusion, blogkit v1.3.1 is in a relatively secure state with no known critical flaws or historical vulnerabilities. Its strengths lie in its avoidance of dangerous functions, secure SQL handling, and limited attack surface. The primary weakness lies in the insufficient output escaping and the complete absence of nonce and capability checks, which, though not directly exploitable with the current data, are foundational security practices that should be addressed to ensure long-term robustness.

Key Concerns

  • Output escaping is only 68% proper
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

BlogKit – Advanced Blog Elements for Elementor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BlogKit – Advanced Blog Elements for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
90
189 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

68% escaped279 total outputs
Attack Surface

BlogKit – Advanced Blog Elements for Elementor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actionplugins_loadedblogkit.php:84
actionadmin_noticesblogkit.php:101
actionadmin_enqueue_scriptsblogkit.php:154
actioncategory_add_form_fieldsblogkit.php:189
actioncategory_edit_form_fieldsblogkit.php:238
actioncreated_categoryblogkit.php:246
actionedited_categoryblogkit.php:247
actionwp_enqueue_scriptsFrontend\Elementor\Assets\Assets.php:48
actionwp_enqueue_scriptsFrontend\Elementor\Assets\Assets.php:49
actionelementor/editor/after_enqueue_stylesFrontend\Elementor\Assets\CustomIcons.php:14
actionelementor/initFrontend\Elementor\Configuration.php:83
actionadmin_noticesFrontend\Elementor\Configuration.php:105
actionadmin_noticesFrontend\Elementor\Configuration.php:110
actionadmin_noticesFrontend\Elementor\Configuration.php:115
actionelementor/widgets/registerFrontend\Elementor\Configuration.php:181
Maintenance & Trust

BlogKit – Advanced Blog Elements for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version8.0
Downloads456

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

BlogKit – Advanced Blog Elements for Elementor Developer Profile

Nexiby LLC

7 plugins · 80 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BlogKit – Advanced Blog Elements for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/blogkit/assets/css/blogkit-frontend.css/wp-content/plugins/blogkit/assets/js/blogkit-frontend.js
Script Paths
/wp-content/plugins/blogkit/assets/js/blogkit-frontend.js
Version Parameters
blogkit/assets/css/blogkit-frontend.css?ver=blogkit/assets/js/blogkit-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
blogkit-category-image-wrap
HTML Comments
<!-- BlogKit Elementor Assets --><!-- BlogKit - Advanced Blog Elements for Elementor -->
Data Attributes
data-blogkit-settings
JS Globals
blogkit_localizeBlogKitFrontend
Shortcode Output
<div class="blogkit-category-image-wrap">
FAQ

Frequently Asked Questions about BlogKit – Advanced Blog Elements for Elementor