
Custom post type templates for Elementor Security & Risk Analysis
wordpress.org/plugins/custom-post-type-templates-for-elementorWith the help of this plug-in you can link you posts or a custom post type detail pages to a normal Elementor page. You can style that Elementor page …
Is Custom post type templates for Elementor Safe to Use in 2026?
Generally Safe
Score 91/100Custom post type templates for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "custom-post-type-templates-for-elementor" v2.0.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, all of which are prepared statements, and it has no known unpatched vulnerabilities. The code also shows a relatively high rate of output escaping, with 75% of outputs properly handled, and no critical or high-severity taint flows were detected, indicating a general effort to prevent common vulnerabilities. However, significant concerns arise from the attack surface analysis. The plugin exposes two AJAX handlers, and critically, both lack authentication checks. This means any unauthenticated user could potentially interact with these handlers, leading to unintended actions or information disclosure.
The vulnerability history, while showing no currently unpatched CVEs, does indicate a past medium vulnerability related to Cross-Site Scripting. The fact that the last vulnerability was recent (November 2024) suggests that the plugin, in its past iterations, has had exploitable flaws, even if they are now addressed. The absence of nonce checks on AJAX handlers is a direct contributor to the potential for Cross-Site Request Forgery (CSRF) attacks, especially given the unauthenticated entry points.
In conclusion, while the plugin has strengths in its handling of SQL and output escaping, the presence of two unprotected AJAX entry points is a serious security weakness that significantly increases the risk of exploitation. The past XSS vulnerability, although patched, also serves as a reminder of potential risks. Addressing the unauthenticated AJAX handlers and implementing nonce checks should be a high priority.
Key Concerns
- AJAX handlers without authentication checks
- Missing nonce checks on AJAX handlers
- Past medium severity XSS vulnerability
- High percentage of unescaped outputs
Custom post type templates for Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Custom post type templates for Elementor <= 1.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Custom post type templates for Elementor Code Analysis
Output Escaping
Custom post type templates for Elementor Attack Surface
AJAX Handlers 2
WordPress Hooks 11
Maintenance & Trust
Custom post type templates for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
Custom post type templates for Elementor Alternatives
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
premium-addons-for-elementor
Elementor Carousel, Mega Menu, Posts List/Slider, Media Gallery, WooCommerce Widgets, Display Conditions, Premade Templates & more.
Royal Addons for Elementor – Addons and Templates Kit for Elementor
royal-elementor-addons
Elementor templates, Header footer builder, Elementor Post Grid, Woocommerce Grid builder, Slider, Forms, Gallery, Nav menu addons, Elementor widgets.
Unlimited Elements For Elementor
unlimited-elements-for-elementor
Elementor all-in-one addons pack with the best widgets for Elementor, offering 100+ free widgets, templates, and tools to create stunning websites!
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
the-plus-addons-for-elementor-page-builder
Best Addons for Elementor with 120+ Elementor FREE & Pro Widgets & 1000+ Elementor Templates with Mega Menu, Post Grid, Header Footer, WooCommerce
Custom post type templates for Elementor Developer Profile
7 plugins · 10K total installs
How We Detect Custom post type templates for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-post-type-templates-for-elementor/styles/main.css/wp-content/plugins/custom-post-type-templates-for-elementor/scripts/main.js/wp-content/plugins/custom-post-type-templates-for-elementor/scripts/main.jscustom-post-type-templates-for-elementor/styles/main.css?ver=custom-post-type-templates-for-elementor/scripts/main.js?ver=HTML / DOM Fingerprints
miga_custom_postsid="miga_custom_post_type_0"name="miga_custom_posts[0][1]"id="miga_custom_post_id_0"name="miga_custom_posts[0][0]"id="miga_custom_post_type_1"name="miga_custom_posts[1][1]"+6 moreobjectL10n