
Cresta Addons for Elementor Security & Risk Analysis
wordpress.org/plugins/cresta-addons-for-elementorDozens of additional widgets for Elementor!
Is Cresta Addons for Elementor Safe to Use in 2026?
Generally Safe
Score 91/100Cresta Addons for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.
The 'cresta-addons-for-elementor' plugin v1.1.1 demonstrates some positive security practices, particularly in its handling of SQL queries, which are exclusively prepared statements, and the absence of dangerous functions or file operations. The static analysis also indicates a controlled attack surface with no identified AJAX handlers, REST API routes, or shortcodes exposed without authentication or proper checks. Capability checks are present, which is a good sign for access control.
However, there are notable areas of concern. The most significant is the relatively low rate of proper output escaping, with only 63% of outputs being escaped. This leaves a substantial portion of the plugin's output potentially vulnerable to Cross-Site Scripting (XSS) attacks, especially given that the plugin's last known vulnerability was of this exact type. The lack of nonce checks on any entry points is also a concern, as it leaves the plugin susceptible to Cross-Site Request Forgery (CSRF) attacks if any unintended actions can be triggered.
Despite the absence of currently unpatched vulnerabilities and a good foundation in SQL security, the history of XSS vulnerabilities coupled with the identified output escaping issues and missing nonce checks suggest a risk of future XSS and CSRF vulnerabilities. While the attack surface is currently small and largely protected, the code quality in output handling needs improvement to mitigate these risks.
Key Concerns
- Low output escaping rate
- No nonce checks on entry points
- History of XSS vulnerabilities
Cresta Addons for Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Cresta Addons for Elementor <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Cresta Addons for Elementor Code Analysis
Output Escaping
Cresta Addons for Elementor Attack Surface
WordPress Hooks 17
Maintenance & Trust
Cresta Addons for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
Cresta Addons for Elementor Alternatives
Qi Addons For Elementor
qi-addons-for-elementor
Qi Addons for Elementor is a comprehensive library of 60+ custom, flexible & easily styled Elementor widgets developed by Qode Interactive.
Addon Elements for Elementor (formerly Elementor Addon Elements)
addon-elements-for-elementor-page-builder
Addon Elements for Elementor comes with 40+ widgets and extensions to extend the power of Elementor Page Builder.
Mega Elements – Addons for Elementor
mega-elements-addons-for-elementor
A powerful and advanced all in one Elementor addons with unique styling features to create a beautiful website effortlessly.
ElementsReady Addons for Elementor
element-ready-lite
ElementsReady Addons for Elementor comes up with ultimate widgets like Post, Accordion, Portfolio, Testimonial, Nav menu, Carousel, Slider etc..
WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More
wpb-elementor-addons
A powerful collection of custom Elementor widgets and extensions to build advanced layouts with ease.
Cresta Addons for Elementor Developer Profile
25 plugins · 22K total installs
How We Detect Cresta Addons for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cresta-addons-for-elementor/assets/css/frontend.css/wp-content/plugins/cresta-addons-for-elementor/assets/js/frontend.js/wp-content/plugins/cresta-addons-for-elementor/assets/css/custom-elementor.css/wp-content/plugins/cresta-addons-for-elementor/assets/js/custom-elementor.js/wp-content/plugins/cresta-addons-for-elementor/panel/css/plugin-options.css/wp-content/plugins/cresta-addons-for-elementor/panel/js/plugin-options.js/wp-content/plugins/cresta-addons-for-elementor/assets/js/frontend.js/wp-content/plugins/cresta-addons-for-elementor/assets/js/custom-elementor.js/wp-content/plugins/cresta-addons-for-elementor/panel/js/plugin-options.jscresta-addons-for-elementor/assets/css/frontend.css?ver=cresta-addons-for-elementor/assets/js/frontend.js?ver=cresta-addons-for-elementor/assets/css/custom-elementor.css?ver=cresta-addons-for-elementor/assets/js/custom-elementor.js?ver=cresta-addons-for-elementor/panel/css/plugin-options.css?ver=cresta-addons-for-elementor/panel/js/plugin-options.js?ver=HTML / DOM Fingerprints
cresta-addons-for-elementorcresta-addons-for-elementor-wrapperdata-cresta-addons-for-elementorcresta_addons_for_elementor_localize