Cresta Addons for Elementor Security & Risk Analysis

wordpress.org/plugins/cresta-addons-for-elementor

Dozens of additional widgets for Elementor!

10 active installs v1.1.1 PHP + WP 4.2+ Updated Dec 17, 2024
addonselementorelementor-addonelementor-widgetelements
91
A · Safe
CVEs total1
Unpatched0
Last CVENov 1, 2024
Safety Verdict

Is Cresta Addons for Elementor Safe to Use in 2026?

Generally Safe

Score 91/100

Cresta Addons for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 1, 2024Updated 1yr ago
Risk Assessment

The 'cresta-addons-for-elementor' plugin v1.1.1 demonstrates some positive security practices, particularly in its handling of SQL queries, which are exclusively prepared statements, and the absence of dangerous functions or file operations. The static analysis also indicates a controlled attack surface with no identified AJAX handlers, REST API routes, or shortcodes exposed without authentication or proper checks. Capability checks are present, which is a good sign for access control.

However, there are notable areas of concern. The most significant is the relatively low rate of proper output escaping, with only 63% of outputs being escaped. This leaves a substantial portion of the plugin's output potentially vulnerable to Cross-Site Scripting (XSS) attacks, especially given that the plugin's last known vulnerability was of this exact type. The lack of nonce checks on any entry points is also a concern, as it leaves the plugin susceptible to Cross-Site Request Forgery (CSRF) attacks if any unintended actions can be triggered.

Despite the absence of currently unpatched vulnerabilities and a good foundation in SQL security, the history of XSS vulnerabilities coupled with the identified output escaping issues and missing nonce checks suggest a risk of future XSS and CSRF vulnerabilities. While the attack surface is currently small and largely protected, the code quality in output handling needs improvement to mitigate these risks.

Key Concerns

  • Low output escaping rate
  • No nonce checks on entry points
  • History of XSS vulnerabilities
Vulnerabilities
1

Cresta Addons for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-51680medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Cresta Addons for Elementor <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 1, 2024 Patched in 1.1.0 (6d)
Code Analysis
Analyzed Mar 16, 2026

Cresta Addons for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
41
69 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

63% escaped110 total outputs
Attack Surface

Cresta Addons for Elementor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionplugins_loadedcresta-addons-for-elementor.php:62
actionadmin_noticescresta-addons-for-elementor.php:75
filterwpml_elementor_widgets_to_translateinc\compatibility\wpml_compatibility.php:42
filtercresta_addons_additional_fieldsinc\config.php:439
actionelementor/widgets/registerinc\widgets.php:42
actionelementor/elements/categories_registeredinc\widgets.php:43
actionelementor/frontend/after_register_scriptsinc\widgets.php:44
actionelementor/frontend/after_register_stylesinc\widgets.php:45
actionelementor/preview/enqueue_scriptsinc\widgets.php:46
actionelementor/preview/enqueue_stylesinc\widgets.php:47
actionelementor/editor/after_enqueue_stylesinc\widgets.php:48
actionelementor/frontend/after_enqueue_scriptsinc\widgets.php:49
filterelementor/editor/localize_settingsinc\widgets.php:50
actionadmin_menupanel\plugin-options-page.php:34
actionadmin_initpanel\plugin-options-page.php:35
actionadmin_enqueue_scriptspanel\plugin-options-page.php:36
filterplugin_row_metapanel\plugin-options-page.php:38
Maintenance & Trust

Cresta Addons for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 17, 2024
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Cresta Addons for Elementor Developer Profile

CrestaProject

25 plugins · 22K total installs

86
trust score
Avg Security Score
97/100
Avg Patch Time
36 days
View full developer profile
Detection Fingerprints

How We Detect Cresta Addons for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cresta-addons-for-elementor/assets/css/frontend.css/wp-content/plugins/cresta-addons-for-elementor/assets/js/frontend.js/wp-content/plugins/cresta-addons-for-elementor/assets/css/custom-elementor.css/wp-content/plugins/cresta-addons-for-elementor/assets/js/custom-elementor.js/wp-content/plugins/cresta-addons-for-elementor/panel/css/plugin-options.css/wp-content/plugins/cresta-addons-for-elementor/panel/js/plugin-options.js
Script Paths
/wp-content/plugins/cresta-addons-for-elementor/assets/js/frontend.js/wp-content/plugins/cresta-addons-for-elementor/assets/js/custom-elementor.js/wp-content/plugins/cresta-addons-for-elementor/panel/js/plugin-options.js
Version Parameters
cresta-addons-for-elementor/assets/css/frontend.css?ver=cresta-addons-for-elementor/assets/js/frontend.js?ver=cresta-addons-for-elementor/assets/css/custom-elementor.css?ver=cresta-addons-for-elementor/assets/js/custom-elementor.js?ver=cresta-addons-for-elementor/panel/css/plugin-options.css?ver=cresta-addons-for-elementor/panel/js/plugin-options.js?ver=

HTML / DOM Fingerprints

CSS Classes
cresta-addons-for-elementorcresta-addons-for-elementor-wrapper
Data Attributes
data-cresta-addons-for-elementor
JS Globals
cresta_addons_for_elementor_localize
FAQ

Frequently Asked Questions about Cresta Addons for Elementor