Elastik Addons for Elementor Security & Risk Analysis

wordpress.org/plugins/elastik-addons-for-elementor

Elastik is a sections/elements framework with high quality and modern design.

10 active installs v0.27 PHP + WP 4.4+ Updated Sep 30, 2018
elementorelementor-addon
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Elastik Addons for Elementor Safe to Use in 2026?

Generally Safe

Score 85/100

Elastik Addons for Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The elastik-addons-for-elementor v0.27 plugin exhibits a generally good security posture based on the provided static analysis. The absence of known vulnerabilities in its history is a strong positive indicator, suggesting a proactive approach to security or a lack of publicly known exploitability. The plugin also demonstrates good practices in handling database interactions, with 100% of SQL queries using prepared statements, which significantly mitigates SQL injection risks. The limited attack surface, consisting of a single shortcode and no unprotected AJAX handlers or REST API routes, further contributes to its perceived security.

However, there are areas that warrant attention. The lack of nonce checks on the single shortcode is a concern, as it could potentially be exploited if the shortcode's functionality is sensitive and can be triggered externally without proper validation. Furthermore, the output escaping is not consistently applied, with 33% of outputs not being properly escaped. This could lead to Cross-Site Scripting (XSS) vulnerabilities if the unescaped data originates from user input or external sources.

In conclusion, while the plugin benefits from a clean vulnerability history and secure database practices, the missing nonce check and the percentage of unescaped output represent potential attack vectors that should be addressed to strengthen its overall security. The absence of dangerous functions, file operations, and external HTTP requests is positive, but the identified weaknesses could be leveraged by attackers.

Key Concerns

  • Shortcode missing nonce checks
  • Improper output escaping
Vulnerabilities
None known

Elastik Addons for Elementor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Elastik Addons for Elementor Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Elastik Addons for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped9 total outputs
Attack Surface

Elastik Addons for Elementor Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[azh_elastik_process_library] azh_elastic.php:944
WordPress Hooks 13
filterupload_mimesazh_elastic.php:13
actionadmin_noticesazh_elastic.php:20
actionadmin_initazh_elastic.php:37
actionazh_loadazh_elastic.php:354
filterwp-less_stylesheet_compute_target_pathazh_elastic.php:360
filterazh_get_content_scriptsazh_elastic.php:367
actionadmin_enqueue_scriptsazh_elastic.php:548
actionwp_enqueue_scriptsazh_elastic.php:558
filterazh_directoryazh_elastic.php:597
filterazh_replacesazh_elastic.php:609
filterazh_settings_sanitize_callbackazh_elastic.php:615
filterazh_get_objectazh_elastic.php:626
filterazh_default_categoryazh_elastic.php:650
Maintenance & Trust

Elastik Addons for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedSep 30, 2018
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Elastik Addons for Elementor Developer Profile

azexo

12 plugins · 150 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Elastik Addons for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/elastik-addons-for-elementor/asset/css/style.css/wp-content/plugins/elastik-addons-for-elementor/asset/css/style.min.css/wp-content/plugins/elastik-addons-for-elementor/asset/js/frontend.js/wp-content/plugins/elastik-addons-for-elementor/asset/js/frontend.min.js
Script Paths
asset/js/frontend.jsasset/js/frontend.min.js
Version Parameters
elastik-addons-for-elementor/asset/css/style.css?ver=elastik-addons-for-elementor/asset/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
azh-elastik-addonsazh-carouselazh-gallery-item
HTML Comments
<!-- Elementor elements --><!-- END Elementor elements --><!-- Widget End --><!-- Widget Start -->
Data Attributes
data-azh-carousel-optionsdata-azh-animation-options
JS Globals
azh_carousel
Shortcode Output
[azh_carousel[azh_gallery
FAQ

Frequently Asked Questions about Elastik Addons for Elementor