Buttons Widget | Full Elementor Security & Risk Analysis

wordpress.org/plugins/buttons-widgets-for-elementor

Buton wigets editor with high-quality beautiful WordPress blocks.

40 active installs v1.1 PHP 5.6+ WP + Updated Jun 15, 2020
button-widgetselementelementorfelfull-elementor
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Buttons Widget | Full Elementor Safe to Use in 2026?

Generally Safe

Score 85/100

Buttons Widget | Full Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "buttons-widgets-for-elementor" v1.1 plugin exhibits a strong security posture based on the provided static analysis. The complete absence of an attack surface (AJAX handlers, REST API routes, shortcodes, cron events) significantly limits potential entry points for attackers. Furthermore, the code signals indicate good development practices, with no dangerous functions identified and all SQL queries utilizing prepared statements. The high percentage of properly escaped output (81%) is also a positive indicator, reducing the risk of cross-site scripting (XSS) vulnerabilities.

However, the analysis does reveal some areas for improvement. The absence of any nonce checks or capability checks across all entry points (though the attack surface is zero) is a concern that, if the attack surface were to grow, could expose the plugin to CSRF or unauthorized action vulnerabilities. The taint analysis returning zero flows is excellent, suggesting no identified issues with unsanitized data leading to critical or high-severity vulnerabilities. The plugin's vulnerability history is clean, with no recorded CVEs, which is a significant strength and indicates a history of stable and secure development.

In conclusion, the plugin is currently in a very secure state due to its minimal attack surface and good coding practices regarding SQL and output escaping. The lack of vulnerabilities in its history is a strong positive. The primary area of concern is the complete absence of nonces and capability checks, which, while not an immediate exploit due to the zero attack surface, represents a potential risk if the plugin were to expand its functionality or if a vulnerability were to be introduced in the future.

Key Concerns

  • No Nonce Checks on Entry Points
  • No Capability Checks on Entry Points
  • Output Escaping Below 100%
Vulnerabilities
None known

Buttons Widget | Full Elementor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Buttons Widget | Full Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
21
89 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

81% escaped110 total outputs
Attack Surface

Buttons Widget | Full Elementor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actioninitButtons.php:26
actionplugins_loadedButtons.php:30
actionadmin_noticesButtons.php:45
actionadmin_noticesButtons.php:53
actionadmin_noticesButtons.php:61
actionelementor/elements/categories_registeredButtons.php:69
actionelementor/editor/after_enqueue_stylesplugin.php:59
actionelementor/frontend/after_register_scriptsplugin.php:64
actionelementor/frontend/after_register_stylesplugin.php:66
actionelementor/preview/enqueue_stylesplugin.php:68
actionelementor/widgets/widgets_registeredplugin.php:72
actionelementor/initplugin.php:73
Maintenance & Trust

Buttons Widget | Full Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJun 15, 2020
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Buttons Widget | Full Elementor Developer Profile

fullelementor

1 plugin · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Buttons Widget | Full Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/buttons-widgets-for-elementor/assets/js/buttons.js/wp-content/plugins/buttons-widgets-for-elementor/assets/css/buttons.css/wp-content/plugins/buttons-widgets-for-elementor/assets/css/admin/styles.css
Script Paths
buttons_widgets_script

HTML / DOM Fingerprints

CSS Classes
buttons-widgets-for-elementor
FAQ

Frequently Asked Questions about Buttons Widget | Full Elementor