
Card Elements for Elementor Security & Risk Analysis
wordpress.org/plugins/card-elements-for-elementorShowcase useful elements with card style for elementor page builder.
Is Card Elements for Elementor Safe to Use in 2026?
Generally Safe
Score 99/100Card Elements for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis for card-elements-for-elementor v1.2.9 indicates a generally good security posture regarding its direct attack surface. The absence of exposed AJAX handlers, REST API routes, shortcodes, and cron events without authentication significantly limits potential entry points for attackers. The code also demonstrates good practices in its use of prepared statements for SQL queries and a high percentage of properly escaped output, along with the absence of dangerous functions, file operations, and external HTTP requests. Capability checks are in place, albeit with a low total count.
However, the vulnerability history is a significant concern. The plugin has a history of two known medium-severity CVEs, both related to Cross-Site Scripting (XSS). While there are no currently unpatched vulnerabilities, the recurring nature of XSS issues in the past suggests a potential for such vulnerabilities to reappear or that the sanitization practices, while good in the static analysis, might have nuances that were missed or were insufficient in previous versions. The lack of nonce checks, while not directly impacting the analyzed entry points (as there are none), combined with only three capability checks, suggests that the overall robustness of security controls might be lower than ideal for a plugin that has previously harbored exploitable flaws.
In conclusion, while card-elements-for-elementor v1.2.9 exhibits strengths in its attack surface management and SQL handling, its historical pattern of XSS vulnerabilities warrants caution. The limited number of capability checks and absence of nonce checks, though not directly linked to exploitable paths in this static analysis, represent areas where security could be further strengthened to prevent recurrence of past issues. The plugin's strengths are in its clean code for core operations, but its past vulnerability history is its primary weakness.
Key Concerns
- History of 2 medium XSS vulnerabilities
- Lack of nonce checks
- Low number of capability checks
- Moderate unescaped output percentage
Card Elements for Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Card Elements for Elementor <= 1.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Profile Card Widget
Card Elements for Elementor <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Card Elements for Elementor Code Analysis
Output Escaping
Data Flow Analysis
Card Elements for Elementor Attack Surface
WordPress Hooks 8
Maintenance & Trust
Card Elements for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
Card Elements for Elementor Alternatives
Card Elements for Elementor Developer Profile
8 plugins · 6K total installs
How We Detect Card Elements for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/card-elements-for-elementor/assets/css/common-card-style.css/wp-content/plugins/card-elements-for-elementor/assets/css/profile-card-style.css/wp-content/plugins/card-elements-for-elementor/assets/css/testimonial-card-style.css/wp-content/plugins/card-elements-for-elementor/assets/css/post-card-style.css/wp-content/plugins/card-elements-for-elementor/assets/css/tour-card-style.css/wp-content/plugins/card-elements-for-elementor/assets/css/listing-card-style.css/wp-content/plugins/card-elements-for-elementor/assets/css/font-awesome.csscard-elements-for-elementor/assets/css/common-card-style.css?ver=card-elements-for-elementor/assets/css/profile-card-style.css?ver=card-elements-for-elementor/assets/css/testimonial-card-style.css?ver=card-elements-for-elementor/assets/css/post-card-style.css?ver=card-elements-for-elementor/assets/css/tour-card-style.css?ver=card-elements-for-elementor/assets/css/listing-card-style.css?ver=card-elements-for-elementor/assets/css/font-awesome.css?ver=HTML / DOM Fingerprints
cee-common-card-stylecee-profile-card-stylecee-testimonial-card-stylecee-post-card-stylecep-tour-card-stylecep-listing-card-stylecee-font-awesome