Bosa Elementor Addons and Templates for WooCommerce Security & Risk Analysis

wordpress.org/plugins/bosa-elementor-for-woocommerce

Elementor Addon with widgets and templates for WooCommerce.

30K active installs v1.0.26 PHP 5.6+ WP 4.0+ Updated Feb 18, 2026
elementor-addonselementor-templateselementor-widgetsone-click-template-importwoocommerce
99
A · Safe
CVEs total1
Unpatched0
Last CVEJun 6, 2024
Safety Verdict

Is Bosa Elementor Addons and Templates for WooCommerce Safe to Use in 2026?

Generally Safe

Score 99/100

Bosa Elementor Addons and Templates for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jun 6, 2024Updated 1mo ago
Risk Assessment

The "bosa-elementor-for-woocommerce" plugin v1.0.26 exhibits a generally strong security posture due to a significant portion of its output being properly escaped and the complete absence of direct SQL queries without prepared statements. The static analysis reveals no critical or high severity taint flows, indicating that user-supplied data is likely handled with care in the analyzed paths. The presence of nonces and capability checks on its AJAX handlers further suggests an effort to secure these entry points.

However, there are areas for improvement. The presence of two unsanitized path flows in the taint analysis, though not reaching critical or high severity, warrants investigation. Additionally, the plugin makes one external HTTP request, which could be a potential vector if not handled securely on the server-side. While there are no currently unpatched vulnerabilities, the plugin has a history of one medium-severity CVE, indicating that past security issues have existed and were addressed. The absence of these past issues being critical or high severity is a positive sign, but the existence of a previous vulnerability means ongoing vigilance is important.

In conclusion, the plugin demonstrates good security practices in several key areas, particularly concerning SQL and output escaping. The limited attack surface and the use of WordPress security features are commendable. Nevertheless, the identified unsanitized path flows and the single external HTTP request represent potential, albeit low-level, risks that should be monitored and addressed. The plugin's history, while indicating past fixes, underscores the need for continuous security updates.

Key Concerns

  • Unsanitized path flows found
  • External HTTP request made
  • 1 Medium CVE in history
Vulnerabilities
1

Bosa Elementor Addons and Templates for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-35724medium · 5.4Missing Authorization

Bosa Elementor Addons and Templates for WooCommerce <= 1.0.12 - Missing Authorization

Jun 6, 2024 Patched in 1.0.13 (7d)
Code Analysis
Analyzed Mar 16, 2026

Bosa Elementor Addons and Templates for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
29
167 escaped
Nonce Checks
7
Capability Checks
11
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

85% escaped196 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
start_importer (includes\bew-importer.php:66)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Bosa Elementor Addons and Templates for WooCommerce Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 5

authwp_ajax_bew_remind_me_laterincludes\admin\notices\pro-notice.php:14
authwp_ajax_bew_upgrade_notice_dismissincludes\admin\notices\pro-notice.php:15
authwp_ajax_bew_rating_maybe_laterincludes\admin\notices\rating-notice.php:14
authwp_ajax_bew_ajax_required_pluginincludes\bew-importer.php:28
authwp_ajax_bew_start_import_templateincludes\bew-importer.php:29
WordPress Hooks 23
actionadmin_noticesbosa-elementor-for-woocommerce.php:63
actionelementor/frontend/after_enqueue_scriptsbosa-elementor-for-woocommerce.php:66
actionelementor/elements/categories_registeredbosa-elementor-for-woocommerce.php:67
actionelementor/widgets/registerbosa-elementor-for-woocommerce.php:68
actionadmin_enqueue_scriptsbosa-elementor-for-woocommerce.php:69
actionelementor/editor/after_enqueue_stylesbosa-elementor-for-woocommerce.php:70
actionelementor/editor/after_enqueue_scriptsbosa-elementor-for-woocommerce.php:71
actionadmin_noticesbosa-elementor-for-woocommerce.php:77
actionadmin_action_elementorbosa-elementor-for-woocommerce.php:79
actionadmin_menubosa-elementor-for-woocommerce.php:82
filterelementor/editor/localize_settingsbosa-elementor-for-woocommerce.php:83
actionafter_setup_themebosa-elementor-for-woocommerce.php:391
actionadmin_enqueue_scriptsincludes\admin\notices\pro-notice.php:12
actionadmin_initincludes\admin\notices\pro-notice.php:13
actionadmin_noticesincludes\admin\notices\pro-notice.php:32
actionadmin_initincludes\admin\notices\rating-notice.php:13
actionadmin_enqueue_scriptsincludes\admin\notices\rating-notice.php:15
actionadmin_initincludes\admin\notices\rating-notice.php:16
actionadmin_noticesincludes\admin\notices\rating-notice.php:36
actionadmin_noticesincludes\admin\notices\rating-notice.php:38
actionadmin_menuincludes\bew-importer.php:26
actionadmin_menuincludes\plugin-info\plugin-info.php:20
actionadmin_enqueue_scriptsincludes\plugin-info\plugin-info.php:23
Maintenance & Trust

Bosa Elementor Addons and Templates for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 18, 2026
PHP min version5.6
Downloads431K

Community Trust

Rating92/100
Number of ratings26
Active installs30K
Developer Profile

Bosa Elementor Addons and Templates for WooCommerce Developer Profile

Bosa Themes

68 plugins · 48K total installs

98
trust score
Avg Security Score
97/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Bosa Elementor Addons and Templates for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bosa-elementor-for-woocommerce/assets/css/panel.css/wp-content/plugins/bosa-elementor-for-woocommerce/assets/js/bew-editor.js
Script Paths
/wp-content/plugins/bosa-elementor-for-woocommerce/assets/js/bew-editor.js
Version Parameters
bosa-elementor-for-woocommerce/assets/css/panel.css?ver=bosa-elementor-for-woocommerce/assets/js/bew-editor.js?ver=

HTML / DOM Fingerprints

CSS Classes
bew-editor-widget-areabew-panel-widget-list
HTML Comments
Main Class File of pluginGet InstanceConstructorWooCommerce Frontend Hooks+4 more
Data Attributes
data-bew-widget-title
JS Globals
bew_panel_localize
FAQ

Frequently Asked Questions about Bosa Elementor Addons and Templates for WooCommerce