DinoPack for Elementor Security & Risk Analysis

wordpress.org/plugins/dinopack-for-elementor

A powerful collection of advanced Elementor widgets including WooCommerce products, Blog layouts, Newsletter with MailChimp and more.

10 active installs v1.0.9 PHP 7.4+ WP 6.6+ Updated Jun 19, 2026
elementormailchimppage-builderwidgetswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DinoPack for Elementor Safe to Use in 2026?

Generally Safe

Score 100/100

DinoPack for Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "dinopack-for-elementor" v1.0.7 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs and its vulnerability history, which shows no prior issues, is a positive indicator. The code demonstrates good practices such as the exclusive use of prepared statements for SQL queries and a very high percentage of properly escaped output, minimizing risks of SQL injection and XSS vulnerabilities. Furthermore, the plugin diligently implements nonce and capability checks for its AJAX handlers, and it has a relatively small attack surface of 19 entry points, all of which appear to be protected.

However, a few areas warrant attention. The presence of file operations and external HTTP requests, while not inherently insecure, represent potential vectors that could be exploited if not implemented with extreme care and robust validation. The analysis also identified 3 external HTTP requests, which could be a concern if these requests are made to untrusted sources or if the data being sent is sensitive. While taint analysis found no unsanitized paths, the very limited number of flows analyzed (2) means it might not have captured all potential issues.

Overall, the plugin appears to be developed with security in mind, especially concerning common web vulnerabilities. The lack of historical vulnerabilities further supports this. The primary potential weaknesses lie in the handling of file operations and external requests, which, although not flagged as vulnerable in this static analysis, always carry a degree of inherent risk.

Key Concerns

  • File operations present
  • External HTTP requests present
Vulnerabilities
None known

DinoPack for Elementor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

DinoPack for Elementor Release Timeline

v1.0.9Current
v1.0.8
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

DinoPack for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
2058 escaped
Nonce Checks
12
Capability Checks
7
File Operations
1
External Requests
3
Bundled Libraries
0

Output Escaping

99% escaped2070 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
dinopack_blog_load_more (inc/class-dinopack-elementor-ajax-handlers.php:15)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

DinoPack for Elementor Attack Surface

Entry Points19
Unprotected0

AJAX Handlers 19

authwp_ajax_wpdino_reset_settingsinc/admin/settings/class-dinopack-settings-page.php:73
authwp_ajax_wpdino_export_settingsinc/admin/settings/class-dinopack-settings-page.php:74
authwp_ajax_wpdino_import_settingsinc/admin/settings/class-dinopack-settings-page.php:75
authwp_ajax_dinopack_blog_load_moreinc/class-dinopack-elementor-ajax-handlers.php:160
noprivwp_ajax_dinopack_blog_load_moreinc/class-dinopack-elementor-ajax-handlers.php:161
authwp_ajax_dinopack_newsletter_subscribeinc/class-dinopack-elementor-ajax-handlers.php:279
noprivwp_ajax_dinopack_newsletter_subscribeinc/class-dinopack-elementor-ajax-handlers.php:280
authwp_ajax_dinopack_newsletter_test_connectioninc/class-dinopack-elementor-ajax-handlers.php:282
noprivwp_ajax_dinopack_newsletter_test_connectioninc/class-dinopack-elementor-ajax-handlers.php:283
authwp_ajax_dinopack_newsletter_get_listsinc/class-dinopack-elementor-ajax-handlers.php:327
noprivwp_ajax_dinopack_newsletter_get_listsinc/class-dinopack-elementor-ajax-handlers.php:328
authwp_ajax_dinopack_generate_product_descriptioninc/class-dinopack-elementor-ajax-handlers.php:446
noprivwp_ajax_dinopack_generate_product_descriptioninc/class-dinopack-elementor-ajax-handlers.php:447
authwp_ajax_dinopack_summarize_product_reviewsinc/class-dinopack-elementor-ajax-handlers.php:552
noprivwp_ajax_dinopack_summarize_product_reviewsinc/class-dinopack-elementor-ajax-handlers.php:553
authwp_ajax_dinopack_generate_product_imageinc/class-dinopack-elementor-ajax-handlers.php:682
noprivwp_ajax_dinopack_generate_product_imageinc/class-dinopack-elementor-ajax-handlers.php:683
authwp_ajax_dinopack_generate_product_seoinc/class-dinopack-elementor-ajax-handlers.php:894
noprivwp_ajax_dinopack_generate_product_seoinc/class-dinopack-elementor-ajax-handlers.php:895
WordPress Hooks 25
actionplugins_loadeddinopack-for-elementor.php:108
actionelementor/editor/before_enqueue_scriptsdinopack-for-elementor.php:110
actionelementor/preview/enqueue_stylesdinopack-for-elementor.php:111
actionelementor/initdinopack-for-elementor.php:173
actionwpdino_dinopack_admin_pageinc/admin/settings/class-dinopack-settings-page.php:69
actionadmin_enqueue_scriptsinc/admin/settings/class-dinopack-settings-page.php:71
actionadmin_initinc/admin/settings/class-dinopack-settings-page.php:72
actioninitinc/admin/settings/class-dinopack-settings-page.php:78
actionadmin_menuinc/class-dinopack-admin-menus.php:41
actionadmin_menuinc/class-dinopack-admin-menus.php:42
actionadmin_headinc/class-dinopack-admin-menus.php:45
actionadmin_footerinc/class-dinopack-admin-menus.php:46
actionadmin_enqueue_scriptsinc/class-dinopack-admin-menus.php:47
actionwp_enqueue_scriptsinc/class-dinopack-elementor-ajax-handlers.php:173
actionwp_enqueue_scriptsinc/class-dinopack-elementor-ajax-handlers.php:340
actionelementor/controls/registerinc/elementor/class-dinopack-elementor-controls.php:57
actionelementor/initinc/elementor/class-dinopack-elementor-widgets.php:52
actionelementor/elements/categories_registeredinc/elementor/class-dinopack-elementor-widgets.php:69
actionelementor/widgets/registerinc/elementor/class-dinopack-elementor-widgets.php:70
actionelementor/editor/after_enqueue_scriptsinc/elementor/widgets/ai-product-description/ai-product-description.php:66
actionelementor/editor/after_enqueue_scriptsinc/elementor/widgets/ai-product-image/ai-product-image.php:66
actionelementor/editor/after_enqueue_scriptsinc/elementor/widgets/ai-product-reviews/ai-product-reviews.php:66
actionelementor/editor/after_enqueue_scriptsinc/elementor/widgets/ai-product-seo/ai-product-seo.php:66
actionelementor/editor/after_enqueue_stylesinc/elementor/widgets/blog/blog.php:71
actionelementor/editor/after_enqueue_stylesinc/elementor/widgets/woo-products/woo-products.php:58
Maintenance & Trust

DinoPack for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedJun 19, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

DinoPack for Elementor Developer Profile

WPDINO

2 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DinoPack for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dinopack-for-elementor/assets/css/dinopack-for-elementor.css
Version Parameters
dinopack-for-elementor/assets/css/dinopack-for-elementor.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about DinoPack for Elementor