Easy Addons for Elementor Security & Risk Analysis

wordpress.org/plugins/easy-addons-for-elementor

Easy Addons For Elementor is a plugin for widgets to extend for Elementor Page Builder.

10 active installs v1.5.0 PHP 7.2+ WP 5.2+ Updated Jan 26, 2026
elementorelementor-page-builderflip-boximage-galleryteam
79
B · Generally Safe
CVEs total1
Unpatched1
Last CVEOct 18, 2024
Safety Verdict

Is Easy Addons for Elementor Safe to Use in 2026?

Mostly Safe

Score 79/100

Easy Addons for Elementor is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Oct 18, 2024Updated 2mo ago
Risk Assessment

The static analysis of easy-addons-for-elementor v1.5.0 shows a generally good security posture, with no identified dangerous functions, raw SQL queries, file operations, or external HTTP requests. The overwhelming majority of output is properly escaped, and the absence of any taint analysis findings for unsanitized paths or critical/high severity issues is positive. However, the plugin's attack surface is notable for its complete lack of authorization checks on any entry points. This, combined with a recent medium-severity Cross-Site Scripting vulnerability that remains unpatched, presents a significant concern.

The vulnerability history indicates a pattern of medium-severity XSS issues, suggesting that input sanitization or output escaping mechanisms might be inconsistent or incomplete in certain scenarios, even though the overall escaping rate appears high. The fact that a recent vulnerability is unpatched means that users of this plugin are currently exposed to a known security flaw. While the code itself seems to employ many good security practices, the lack of access control on entry points and the presence of an unpatched CVE are critical weaknesses that overshadow these strengths.

Key Concerns

  • Unpatched CVE (medium severity)
  • No capability checks on entry points
  • Minor unescaped output (1% of 366)
Vulnerabilities
1

Easy Addons for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2024 · unpatched
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-49631medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Easy Addons for Elementor <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Oct 18, 2024Unpatched
Code Analysis
Analyzed Mar 17, 2026

Easy Addons for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
364 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped366 total outputs
Attack Surface

Easy Addons for Elementor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionplugins_loadedincludes\classes\class-easy-addons.php:142
actionadmin_enqueue_scriptsincludes\classes\class-easy-addons.php:157
actionadmin_enqueue_scriptsincludes\classes\class-easy-addons.php:158
actionwp_enqueue_scriptsincludes\classes\class-easy-addons.php:173
actionwp_enqueue_scriptsincludes\classes\class-easy-addons.php:174
actionelementor/frontend/after_register_scriptswidgets\class-easy-addons-widget.php:56
actionelementor/widgets/registerwidgets\class-easy-addons-widget.php:59
actionelementor/elements/categories_registeredwidgets\class-easy-addons-widget.php:65
Maintenance & Trust

Easy Addons for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 26, 2026
PHP min version7.2
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Easy Addons for Elementor Developer Profile

Md Abdul Kader

7 plugins · 270 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy Addons for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-addons-for-elementor/admin/css/easy-addons-admin.css/wp-content/plugins/easy-addons-for-elementor/admin/js/easy-addons-admin.js/wp-content/plugins/easy-addons-for-elementor/public/css/easy-addons-public.css/wp-content/plugins/easy-addons-for-elementor/public/js/easy-addons-public.js
Script Paths
admin/js/easy-addons-admin.jspublic/js/easy-addons-public.js
Version Parameters
easy-addons-for-elementor/admin/css/easy-addons-admin.css?ver=easy-addons-for-elementor/admin/js/easy-addons-admin.js?ver=easy-addons-for-elementor/public/css/easy-addons-public.css?ver=easy-addons-for-elementor/public/js/easy-addons-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
eael-addons-wrapper
Data Attributes
data-easy-addons-id
JS Globals
EasyAddons
FAQ

Frequently Asked Questions about Easy Addons for Elementor