Design Tokens Manager for Elementor Security & Risk Analysis

wordpress.org/plugins/design-tokens-manager-for-elementor

Manage Elementor Global Colors and Fonts with clamp() support, ID preservation, bulk editing, and seamless Site Settings sync.

0 active installs v1.5.1 PHP 7.0+ WP 5.6+ Updated Dec 1, 2025
colorsdesignelementortokenstypography
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Design Tokens Manager for Elementor Safe to Use in 2026?

Generally Safe

Score 100/100

Design Tokens Manager for Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "design-tokens-manager-for-elementor" plugin v1.5.1 exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by having all identified AJAX handlers protected with authentication checks and utilizing prepared statements for all SQL queries. The high percentage of properly escaped output and the presence of nonce and capability checks further reinforce this positive assessment. The absence of any recorded vulnerabilities, critical taint flows, or dangerous functions is a significant strength.

While the static analysis reveals a minimal attack surface with no immediately apparent critical vulnerabilities, a few areas warrant attention. The presence of four file operations, though not explicitly flagged as problematic, could represent a potential avenue for insecure operations if not handled with extreme care. Similarly, while output is largely escaped, the 4% that is not could still pose a risk in specific contexts. The plugin also does not bundle any third-party libraries, which eliminates the risk of using outdated and vulnerable components but also means the developers are responsible for all code. The lack of any historical vulnerabilities is a very positive sign, suggesting a mature and security-conscious development process.

In conclusion, this plugin appears to be well-developed from a security perspective. The minimal attack surface, robust use of security features like nonces and capability checks, and clean vulnerability history are all strong indicators of a secure product. The minor concerns around file operations and unescaped output are typical for many plugins and do not appear to present a high immediate risk given the other security measures in place. The developers have clearly prioritized security in the implementation.

Key Concerns

  • Unescaped output detected (4%)
  • File operations detected (4)
Vulnerabilities
None known

Design Tokens Manager for Elementor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Design Tokens Manager for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
115 escaped
Nonce Checks
6
Capability Checks
7
File Operations
4
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped120 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
edtm_handle_export_tokens (admin\import-export.php:216)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Design Tokens Manager for Elementor Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_edtm_update_sectiondesign-tokens-manager-for-elementor.php:134
WordPress Hooks 10
actionadmin_menudesign-tokens-manager-for-elementor.php:76
actionadmin_enqueue_scriptsdesign-tokens-manager-for-elementor.php:110
actionadmin_post_edtm_save_tokensdesign-tokens-manager-for-elementor.php:138
actionadmin_post_edtm_export_tokensdesign-tokens-manager-for-elementor.php:142
actionadmin_post_edtm_import_tokensdesign-tokens-manager-for-elementor.php:143
actionadmin_post_edtm_pull_from_kitdesign-tokens-manager-for-elementor.php:144
actionadmin_post_edtm_push_to_kitdesign-tokens-manager-for-elementor.php:145
actionadmin_initdesign-tokens-manager-for-elementor.php:148
actionelementor/loadeddesign-tokens-manager-for-elementor.php:149
actionadmin_noticesdesign-tokens-manager-for-elementor.php:197
Maintenance & Trust

Design Tokens Manager for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 1, 2025
PHP min version7.0
Downloads127

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Design Tokens Manager for Elementor Developer Profile

nes07

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Design Tokens Manager for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/design-tokens-manager-for-elementor/assets/css/admin.css/wp-content/plugins/design-tokens-manager-for-elementor/assets/js/admin.js
Script Paths
/wp-content/plugins/design-tokens-manager-for-elementor/assets/js/admin.js
Version Parameters
design-tokens-manager-for-elementor/assets/css/admin.css?ver=design-tokens-manager-for-elementor/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
edtm-section-colorsedtm-section-fonts
Data Attributes
data-section
JS Globals
EDTM_I18NEDTM_ADMIN
REST Endpoints
/wp-json/design-tokens-manager-for-elementor/v1/tokens
FAQ

Frequently Asked Questions about Design Tokens Manager for Elementor