
ElementsCSS Addons for Elementor (Elementor Widgets Extender & Addons) Security & Risk Analysis
wordpress.org/plugins/css-for-elementorExtends existing Elementor and Elementor Pro Widgets, adds more useful new Widgets, features that saves your valuable time.
Is ElementsCSS Addons for Elementor (Elementor Widgets Extender & Addons) Safe to Use in 2026?
Use With Caution
Score 56/100ElementsCSS Addons for Elementor (Elementor Widgets Extender & Addons) has 2 unpatched vulnerabilities. Evaluate alternatives or apply available mitigations.
The "css-for-elementor" plugin, version 1.0.8.9, presents a mixed security posture. While it demonstrates good practices in handling SQL queries with prepared statements and avoids dangerous functions and file operations, significant concerns arise from its attack surface and output escaping. A substantial number of AJAX handlers (7 out of 7) lack authentication checks, creating a broad entry point for potential exploitation. Furthermore, only 41% of outputs are properly escaped, suggesting a considerable risk of Cross-Site Scripting (XSS) vulnerabilities where user-supplied data might not be neutralized before being rendered on a webpage. The plugin's history of known vulnerabilities, including SSRF and XSS, with two currently unpatched (one high and one medium severity), further exacerbates these concerns. This pattern indicates recurring security weaknesses that have not been fully addressed, despite previous remediation efforts. The combination of a large, unprotected attack surface, insufficient output escaping, and a history of critical vulnerability types points to a plugin that requires immediate attention to mitigate potential risks.
Key Concerns
- Unpatched CVEs
- Unprotected AJAX handlers
- Low percentage of properly escaped output
- Missing nonce checks on AJAX
- Unsanitized paths in taint analysis
ElementsCSS Addons for Elementor (Elementor Widgets Extender & Addons) Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
ElementsCSS Addons for Elementor <= 1.0.8.7 - Unauthenticated Server-Side Request Forgery
ElementsCSS Addons for Elementor <= 1.0.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
ElementsCSS Addons for Elementor (Elementor Widgets Extender & Addons) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ElementsCSS Addons for Elementor (Elementor Widgets Extender & Addons) Attack Surface
AJAX Handlers 7
Shortcodes 1
WordPress Hooks 56
Maintenance & Trust
ElementsCSS Addons for Elementor (Elementor Widgets Extender & Addons) Maintenance & Trust
Maintenance Signals
Community Trust
ElementsCSS Addons for Elementor (Elementor Widgets Extender & Addons) Alternatives
WPBITS Addons For Elementor Page Builder
wpbits-addons-for-elementor
Addons for Elementor Page Builder.
Sidebars for Hello Elementor Theme
sidebars-for-helloelementortheme
This plugin comes with 6 responsive sidebars for just about everything you need to use anywhere within your website built using Elementor and Hello El …
Creative Elements for Elementor
creative-elements-for-elementor
Creative Elements for Elementor - Absolutely Free Elementor Addons Creative Elements for Elementor is the creative addons collection for the Elemento …
Qi Addons For Elementor
qi-addons-for-elementor
Qi Addons for Elementor is a comprehensive library of 60+ custom, flexible & easily styled Elementor widgets developed by Qode Interactive.
Livemesh Addons by Elementor
addons-for-elementor
Elementor Addons that saves time with multiple ready-to-use drag and drop styles for 30+ essential widgets built for Elementor page builder.
ElementsCSS Addons for Elementor (Elementor Widgets Extender & Addons) Developer Profile
4 plugins · 210 total installs
How We Detect ElementsCSS Addons for Elementor (Elementor Widgets Extender & Addons)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/css-for-elementor/admin/css/custom.css/wp-content/plugins/css-for-elementor/admin/css/review.css/wp-content/plugins/css-for-elementor/admin/js/custom.js/wp-content/plugins/css-for-elementor/admin/js/review.js/wp-content/plugins/css-for-elementor/admin/js/custom.js/wp-content/plugins/css-for-elementor/admin/js/review.jscss-for-elementor/admin/css/custom.css?ver=css-for-elementor/admin/css/review.css?ver=css-for-elementor/admin/js/custom.js?ver=css-for-elementor/admin/js/review.js?ver=HTML / DOM Fingerprints
cssfe-reviewcssfe-review-noticereview-logoplu-logoid="cssfeReviewAlreadyDid"id="cssfeMaybeLater"id="cssfeNeverShowAgain"window.cssfeReviewAlreadyDidwindow.cssfeMaybeLaterwindow.cssfeNeverShowAgain