Easy Elements Hider Security & Risk Analysis

wordpress.org/plugins/easy-elements-hider

Easy Elements Hider allows you to hide elements on your website easily without editing style.css file. It's user-friendly, and you have to add o …

200 active installs v2.0 PHP + WP 3.0.1+ Updated Feb 12, 2022
css-classcss-idwebsite-elements-hiderwebsite-sections-hide
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEJul 4, 2025
Download
Safety Verdict

Is Easy Elements Hider Safe to Use in 2026?

Use With Caution

Score 63/100

Easy Elements Hider has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Jul 4, 2025Updated 4yr ago
Risk Assessment

The "easy-elements-hider" plugin v2.0 exhibits a mixed security posture. On the positive side, the static analysis reveals no identified dangerous functions, no raw SQL queries, no file operations, and no external HTTP requests, which are good indicators of secure coding practices. The absence of a large attack surface from AJAX handlers, REST API routes, and shortcodes is also a positive sign, suggesting limited points of potential entry. However, a significant concern arises from the very low percentage of properly escaped output (20%). This indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, especially considering the historical vulnerability data.

Key Concerns

  • Unpatched CVE exists
  • Low output escaping percentage
  • No capability checks
  • No nonce checks
Vulnerabilities
1

Easy Elements Hider Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-28971medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Easy Elements Hider <= 2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

Jul 4, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Easy Elements Hider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

20% escaped10 total outputs
Attack Surface

Easy Elements Hider Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterplugin_row_metaencore.php:11
actionwp_print_stylesencore.php:36
actionadmin_initencore.php:45
actionadmin_menuencore.php:51
Maintenance & Trust

Easy Elements Hider Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedFeb 12, 2022
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

Easy Elements Hider Developer Profile

CWD Web Designer

2 plugins · 210 total installs

81
trust score
Avg Security Score
82/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy Elements Hider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-elements-hider/encore.php

HTML / DOM Fingerprints

Data Attributes
id="encore_easy_elements_hider_hidden_elements_selectors[name="encore_easy_elements_hider_hidden_elements_selectors[id="encore_easy_elements_hider_settings_row[id="encore_easy_elements_hider_settings_table"
JS Globals
window.encore_easy_elements_hider_settings_element_countwindow.encore_easy_elements_hider_settings_add_elementwindow.encore_easy_elements_hider_settings_remove_element
FAQ

Frequently Asked Questions about Easy Elements Hider