
ButtonZ – Elementor Addon Security & Risk Analysis
wordpress.org/plugins/buttonzLive Demo
Is ButtonZ – Elementor Addon Safe to Use in 2026?
Generally Safe
Score 85/100ButtonZ – Elementor Addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "buttonz" v1.0.2 plugin exhibits a mixed security posture. On the positive side, it does not have any known CVEs and all its SQL queries utilize prepared statements, indicating good practices in database interaction. Furthermore, the absence of file operations, external HTTP requests, and bundled libraries are also strengths. However, the plugin has a significant security concern with one AJAX handler lacking any authentication checks, exposing a direct entry point for potential exploitation.
The static analysis reveals that while the attack surface is small, one of its entry points is unprotected, which is a notable weakness. The code signals also highlight that only 18% of output is properly escaped, suggesting a risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of nonce checks on the unprotected AJAX handler further compounds this risk, making it easier for attackers to submit malicious requests.
Given the lack of any recorded vulnerability history, it is difficult to draw definitive conclusions about its past security patterns. However, the presence of an unprotected AJAX handler and poor output escaping in the current version suggest that while it may have avoided past issues, it is not inherently robust against common web vulnerabilities. The plugin demonstrates some good practices but has critical areas requiring immediate attention, particularly the unprotected AJAX endpoint and insufficient output sanitization.
Key Concerns
- Unprotected AJAX handler
- Low percentage of properly escaped output
- Missing nonce checks on AJAX
ButtonZ – Elementor Addon Security Vulnerabilities
ButtonZ – Elementor Addon Code Analysis
Output Escaping
ButtonZ – Elementor Addon Attack Surface
AJAX Handlers 1
WordPress Hooks 14
Maintenance & Trust
ButtonZ – Elementor Addon Maintenance & Trust
Maintenance Signals
Community Trust
ButtonZ – Elementor Addon Alternatives
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
premium-addons-for-elementor
Elementor Carousel, Mega Menu, Posts List/Slider, Media Gallery, WooCommerce Widgets, Display Conditions, Premade Templates & more.
Royal Addons for Elementor – Addons and Templates Kit for Elementor
royal-elementor-addons
Elementor templates, Header footer builder, Elementor Post Grid, Woocommerce Grid builder, Slider, Forms, Gallery, Nav menu addons, Elementor widgets.
ButtonZ – Elementor Addon Developer Profile
2 plugins · 10 total installs
How We Detect ButtonZ – Elementor Addon
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buttonz/assets/css/admin.css/wp-content/plugins/buttonz/assets/admin.js/wp-content/plugins/buttonz/assets/icon.png/wp-content/plugins/buttonz/assets/css/style.css/wp-content/plugins/buttonz/assets/css/animate.css/wp-content/plugins/buttonz/assets/css/hover-min.css/wp-content/plugins/buttonz/assets/vendors/themify-icon/themify-icon.css/wp-content/plugins/buttonz/assets/vendors/icomoon/style.css+2 more/wp-content/plugins/buttonz/assets/admin.jsbuttonz/assets/css/admin.css?ver=buttonz/assets/admin.js?ver=buttonz/assets/css/style.css?ver=buttonz/assets/css/animate.css?ver=buttonz/assets/css/hover-min.css?ver=buttonz/assets/vendors/themify-icon/themify-icon.css?ver=buttonz/assets/vendors/icomoon/style.css?ver=buttonz/assets/vendors/elegant-icon/style.css?ver=HTML / DOM Fingerprints
ub-noticeub-iconimgub-doneelementor-widget-ultimate-buttondata-elementor-iddata-elementor-post-typedata-elementor-typedata-elementor-device-modedata-elementor-settingsdata-elementor-animationButtonZ