Elemendas Addons Security & Risk Analysis

wordpress.org/plugins/elemendas-addons

This addon for Elementor allows you to display the number of results of the search query, as well as to highlight the searched string in the results.

60 active installs v2.3.3.1 PHP 5.6+ WP 5.0+ Updated Apr 20, 2025
carouselelementorelementor-widgetsmenusearch-results
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Elemendas Addons Safe to Use in 2026?

Generally Safe

Score 100/100

Elemendas Addons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "elemendas-addons" v2.3.3.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs and the complete lack of taint analysis findings suggest a well-maintained and secure codebase. Furthermore, the plugin demonstrates good practices by not utilizing dangerous functions, implementing prepared statements for all SQL queries, and performing file operations and nonces. The presence of external HTTP requests and bundled libraries are also zero, further reducing potential attack vectors.

However, there are areas for improvement. A significant concern is the lack of capability checks, especially given the file operation. This could potentially lead to unauthorized access or modification if the file operation itself is not sufficiently secured against arbitrary file access. While the output escaping is at 65%, this still leaves 35% of outputs potentially vulnerable to cross-site scripting (XSS) if they are user-controlled. The absence of any identified attack surface entries (AJAX, REST API, shortcodes) is positive, but this could also indicate limited functionality or a less feature-rich plugin.

Overall, the plugin appears to be on a positive security trajectory with no critical or high-severity issues immediately apparent from the static analysis or vulnerability history. The main risks revolve around potential XSS vulnerabilities due to incomplete output escaping and the implications of the file operation without explicit capability checks. Addressing these areas would further solidify its security.

Key Concerns

  • Unescaped output detected
  • File operation without capability check
Vulnerabilities
None known

Elemendas Addons Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Elemendas Addons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
26 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

65% escaped40 total outputs
Attack Surface

Elemendas Addons Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 39
actionplugins_loadedelemendas-addons.php:42
actionacf/include_field_typesincludes\acf\acf-svg-icon-field.php:26
actionadmin_menuincludes\acf\acf-svg-icons-upload.php:19
actionadmin_noticesincludes\acf\acf-svg-icons-upload.php:20
filterupload_dirincludes\acf\acf-svg-icons-upload.php:81
filterupload_mimesincludes\acf\acf-svg-icons-upload.php:82
actionelementor/initincludes\plugin.php:81
actionadmin_enqueue_scriptsincludes\plugin.php:132
actionadmin_noticesincludes\plugin.php:136
actionadmin_noticesincludes\plugin.php:141
actionadmin_noticesincludes\plugin.php:146
actionadmin_noticesincludes\plugin.php:151
actionadmin_noticesincludes\plugin.php:156
actionadmin_noticesincludes\plugin.php:161
actionadmin_noticesincludes\plugin.php:166
actionadmin_noticesincludes\plugin.php:177
actionadmin_noticesincludes\plugin.php:182
actionadmin_noticesincludes\plugin.php:190
actionadmin_noticesincludes\plugin.php:195
actionelementor/widgets/registerincludes\plugin.php:413
actionelementor/controls/registerincludes\plugin.php:415
actionelementor/editor/after_enqueue_stylesincludes\plugin.php:417
actionelementor/preview/enqueue_stylesincludes\plugin.php:419
filterthe_titleincludes\widgets\added\search-results-highlighted.php:549
filterthe_excerptincludes\widgets\added\search-results-highlighted.php:551
actionelementor/element/nav-menu/section_layout/before_section_endincludes\widgets\extended\fancy-nav-menu.php:14
actionelementor/element/nav-menu/section_style_dropdown/before_section_endincludes\widgets\extended\fancy-nav-menu.php:17
filterelementor/widget/render_contentincludes\widgets\extended\fancy-nav-menu.php:21
actionelementor/frontend/after_enqueue_stylesincludes\widgets\extended\fancy-nav-menu.php:24
filternav_menu_link_attributesincludes\widgets\extended\fancy-nav-menu.php:208
filternav_menu_link_attributesincludes\widgets\extended\fancy-nav-menu.php:209
filternav_menu_submenu_css_classincludes\widgets\extended\fancy-nav-menu.php:210
filternav_menu_item_titleincludes\widgets\extended\fancy-nav-menu.php:211
filternav_menu_item_idincludes\widgets\extended\fancy-nav-menu.php:212
actionelementor/element/theme-archive-title/section_title/after_section_endincludes\widgets\extended\search-results-archive-title.php:16
actionelementor/element/theme-archive-title/section_title_style/before_section_startincludes\widgets\extended\search-results-archive-title.php:17
actionelementor/element/theme-archive-title/section_title_style/after_section_endincludes\widgets\extended\search-results-archive-title.php:18
filterelementor/widget/render_contentincludes\widgets\extended\search-results-archive-title.php:21
filterelementor/widget/print_templateincludes\widgets\extended\search-results-archive-title.php:22
Maintenance & Trust

Elemendas Addons Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 20, 2025
PHP min version5.6
Downloads3K

Community Trust

Rating100/100
Number of ratings4
Active installs60
Developer Profile

Elemendas Addons Developer Profile

Santiago Becerra

2 plugins · 160 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Elemendas Addons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/elemendas-addons/assets/css/uploadSVG.css/wp-content/plugins/elemendas-addons/assets/js/uploadSVG.js
Script Paths
/wp-content/plugins/elemendas-addons/includes/acf/assets/js/icon-picker.js/wp-content/plugins/elemendas-addons/includes/acf/assets/js/icon-picker-admin.js
Version Parameters
elemendas-addons/style.css?ver=elemendas-addons/script.js?ver=elemendas-addons/assets/css/uploadSVG.css?ver=elemendas-addons/assets/js/uploadSVG.js?ver=

HTML / DOM Fingerprints

CSS Classes
elemendas-addons
Data Attributes
data-id='icon-picker'
JS Globals
ElemendasElmIconPicker
FAQ

Frequently Asked Questions about Elemendas Addons