Frontend Post for Elementor Security & Risk Analysis

wordpress.org/plugins/dj-elementor-frontend

This plugin is extension for Elementor, it creates new widget called "Frontend Post" which you can use to provide functionality for frontend …

10 active installs v1.2 PHP + WP + Updated Jan 5, 2018
apielementorfrontendfrontend-postpost
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Frontend Post for Elementor Safe to Use in 2026?

Generally Safe

Score 85/100

Frontend Post for Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The static analysis of dj-elementor-frontend v1.2 reveals a promising security posture with no identified attack vectors through AJAX, REST API, shortcodes, or cron events. The absence of dangerous functions and file operations is also a positive sign. Furthermore, all SQL queries are properly prepared, and there are no recorded vulnerabilities in its history, suggesting a development team that prioritizes secure coding practices and has a history of addressing security issues promptly or not introducing them. However, a significant concern arises from the complete lack of output escaping, meaning all 16 identified outputs are potentially vulnerable to cross-site scripting (XSS) attacks. While capability checks are present, the lack of nonce checks on entry points, if any were present, combined with unescaped output, creates a significant risk.

The primary concern stems from the unescaped output. Even with a minimal attack surface and no known vulnerabilities, a single unpatched XSS vulnerability can be highly damaging. The absence of taint analysis results is noted, but this could also indicate that the analysis tools did not find any exploitable flows, or that the analysis was incomplete. The plugin's reliance on the TinyMCE bundled library, while common, could also introduce risks if it becomes outdated and has known vulnerabilities, though this is not explicitly stated as an issue in the provided data. The lack of critical or high-severity issues in the history is a strong positive, but the current static analysis findings, particularly the output escaping, warrant careful attention.

Key Concerns

  • 0% of outputs properly escaped
  • No nonce checks on entry points
  • Bundled TinyMCE library
Vulnerabilities
None known

Frontend Post for Elementor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Frontend Post for Elementor Release Timeline

v1.2Current
v1.1
v1.0
Code Analysis
Analyzed Mar 17, 2026

Frontend Post for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

0% escaped16 total outputs
Attack Surface

Frontend Post for Elementor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_noticesdj-frontend-post.php:29
actionadmin_noticesdj-frontend-post.php:36
actionplugins_loadeddj-frontend-post.php:43
actionwp_enqueue_scriptsdj-frontend-post.php:65
filtermce_cssdj-frontend-post.php:94
actionelementor/widgets/widgets_registeredplugin.php:37
actionelementor/frontend/after_register_scriptsplugin.php:39
Maintenance & Trust

Frontend Post for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedJan 5, 2018
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Frontend Post for Elementor Developer Profile

djekanovic

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Frontend Post for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dj-elementor-frontend/assets/js/ajax.js/wp-content/plugins/dj-elementor-frontend/assets/css/default.css
Script Paths
/wp-content/plugins/dj-elementor-frontend/assets/js/ajax.js/wp-content/plugins/dj-elementor-frontend/assets/js/tiny-backend.js
Version Parameters
dj-elementor-frontend/assets/js/ajax.js?ver=dj-elementor-frontend/assets/css/default.css?ver=

HTML / DOM Fingerprints

JS Globals
POST_SUBMITTER
REST Endpoints
/wp-json/
FAQ

Frequently Asked Questions about Frontend Post for Elementor