Card Elements for Elementor Security & Risk Analysis

wordpress.org/plugins/card-elements-for-elementor

Showcase useful elements with card style for elementor page builder.

3K active installs v1.2.9 PHP 8.0+ WP 4.4+ Updated Oct 10, 2025
card-elements-modulecustom-listing-card-widgetcustom-profile-card-widgetcustom-testimonial-card-widgetfree-elementor-addon
99
A · Safe
CVEs total2
Unpatched0
Last CVEFeb 26, 2025
Safety Verdict

Is Card Elements for Elementor Safe to Use in 2026?

Generally Safe

Score 99/100

Card Elements for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Feb 26, 2025Updated 5mo ago
Risk Assessment

The static analysis for card-elements-for-elementor v1.2.9 indicates a generally good security posture regarding its direct attack surface. The absence of exposed AJAX handlers, REST API routes, shortcodes, and cron events without authentication significantly limits potential entry points for attackers. The code also demonstrates good practices in its use of prepared statements for SQL queries and a high percentage of properly escaped output, along with the absence of dangerous functions, file operations, and external HTTP requests. Capability checks are in place, albeit with a low total count.

However, the vulnerability history is a significant concern. The plugin has a history of two known medium-severity CVEs, both related to Cross-Site Scripting (XSS). While there are no currently unpatched vulnerabilities, the recurring nature of XSS issues in the past suggests a potential for such vulnerabilities to reappear or that the sanitization practices, while good in the static analysis, might have nuances that were missed or were insufficient in previous versions. The lack of nonce checks, while not directly impacting the analyzed entry points (as there are none), combined with only three capability checks, suggests that the overall robustness of security controls might be lower than ideal for a plugin that has previously harbored exploitable flaws.

In conclusion, while card-elements-for-elementor v1.2.9 exhibits strengths in its attack surface management and SQL handling, its historical pattern of XSS vulnerabilities warrants caution. The limited number of capability checks and absence of nonce checks, though not directly linked to exploitable paths in this static analysis, represent areas where security could be further strengthened to prevent recurrence of past issues. The plugin's strengths are in its clean code for core operations, but its past vulnerability history is its primary weakness.

Key Concerns

  • History of 2 medium XSS vulnerabilities
  • Lack of nonce checks
  • Low number of capability checks
  • Moderate unescaped output percentage
Vulnerabilities
2

Card Elements for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-13734medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Card Elements for Elementor <= 1.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Profile Card Widget

Feb 26, 2025 Patched in 1.2.7 (1d)
CVE-2024-43123medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Card Elements for Elementor <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Aug 7, 2024 Patched in 1.2.3 (8d)
Code Analysis
Analyzed Mar 16, 2026

Card Elements for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
42
234 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

85% escaped276 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
<elementor-listing-card-1> (include\listing-card\elementor-listing-card-1.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Card Elements for Elementor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionelementor/widgets/widgets_registeredcard-elements-for-elementor.php:44
actionwp_enqueue_scriptscard-elements-for-elementor.php:93
actionelementor/editor/after_enqueue_stylescard-elements-for-elementor.php:116
actionadmin_noticescard-elements-for-elementor.php:131
actionadmin_noticescard-elements-for-elementor.php:136
actionplugins_loadedcard-elements-for-elementor.php:142
actionadmin_noticescard-elements-for-elementor.php:247
actionelementor/initwidgets\elementor-helper.php:15
Maintenance & Trust

Card Elements for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 10, 2025
PHP min version8.0
Downloads76K

Community Trust

Rating100/100
Number of ratings10
Active installs3K
Developer Profile

Card Elements for Elementor Developer Profile

Techeshta

8 plugins · 6K total installs

98
trust score
Avg Security Score
97/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect Card Elements for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/card-elements-for-elementor/assets/css/common-card-style.css/wp-content/plugins/card-elements-for-elementor/assets/css/profile-card-style.css/wp-content/plugins/card-elements-for-elementor/assets/css/testimonial-card-style.css/wp-content/plugins/card-elements-for-elementor/assets/css/post-card-style.css/wp-content/plugins/card-elements-for-elementor/assets/css/tour-card-style.css/wp-content/plugins/card-elements-for-elementor/assets/css/listing-card-style.css/wp-content/plugins/card-elements-for-elementor/assets/css/font-awesome.css
Version Parameters
card-elements-for-elementor/assets/css/common-card-style.css?ver=card-elements-for-elementor/assets/css/profile-card-style.css?ver=card-elements-for-elementor/assets/css/testimonial-card-style.css?ver=card-elements-for-elementor/assets/css/post-card-style.css?ver=card-elements-for-elementor/assets/css/tour-card-style.css?ver=card-elements-for-elementor/assets/css/listing-card-style.css?ver=card-elements-for-elementor/assets/css/font-awesome.css?ver=

HTML / DOM Fingerprints

CSS Classes
cee-common-card-stylecee-profile-card-stylecee-testimonial-card-stylecee-post-card-stylecep-tour-card-stylecep-listing-card-stylecee-font-awesome
FAQ

Frequently Asked Questions about Card Elements for Elementor