Caldera Forms styler for Elementor Page Builder Security & Risk Analysis

wordpress.org/plugins/elementor-caldera-forms

Caldera Forms styler for Elementor page builder.

800 active installs v1.0.0 PHP + WP 4.0+ Updated Dec 3, 2017
caldera-formscaldera-forms-stylerelementorelementor-addonelementor-widget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Caldera Forms styler for Elementor Page Builder Safe to Use in 2026?

Generally Safe

Score 85/100

Caldera Forms styler for Elementor Page Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin 'elementor-caldera-forms' v1.0.0 exhibits a generally good security posture with no recorded vulnerabilities and several strong security practices in place. The analysis shows no critical or high severity taint flows, zero known CVEs, and all entry points (AJAX handlers) appear to have nonce and capability checks. This indicates a proactive approach to security and diligent coding standards. However, there are some areas that warrant attention. The presence of the `unserialize` function is a known risk, as it can lead to object injection vulnerabilities if not handled with extreme caution and strict input validation. Additionally, the plugin uses a raw SQL query without prepared statements, which is a significant risk for SQL injection. While the total number of outputs is small, the 50% rate of improperly escaped output increases the risk of cross-site scripting (XSS) vulnerabilities. The lack of vulnerabilities in its history is a positive sign, but the identified code signals suggest potential weaknesses that could be exploited. The plugin benefits from a small attack surface and the presence of security checks, but the critical functions and data handling practices need to be reviewed and improved to mitigate the identified risks.

Key Concerns

  • Raw SQL query without prepared statements
  • Dangerous function `unserialize` used
  • 50% of outputs are not properly escaped
Vulnerabilities
None known

Caldera Forms styler for Elementor Page Builder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Caldera Forms styler for Elementor Page Builder Code Analysis

Dangerous Functions
1
Raw SQL Queries
1
0 prepared
Unescaped Output
8
8 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$unserialize = unserialize( $form->config );includes\queries.php:11

SQL Query Safety

0% prepared1 total queries

Output Escaping

50% escaped16 total outputs
Attack Surface

Caldera Forms styler for Elementor Page Builder Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_eael_caldera_forms_upsell_installerincludes\eael-caldera-forms-upsell.php:35
authwp_ajax_eael_caldera_forms_installerincludes\eael-caldera-forms-upsell.php:36
WordPress Hooks 8
actionadmin_menuadmin\settings.php:41
actioninitadmin\settings.php:42
actionelementor/widgets/widgets_registeredelementor-caldera-forms.php:37
actionwp_enqueue_scriptselementor-caldera-forms.php:47
actionadmin_noticeselementor-caldera-forms.php:61
actioninitincludes\eael-caldera-forms-upsell.php:15
actionadmin_noticesincludes\eael-caldera-forms-upsell.php:33
actionelementor/initincludes\elementor-helper.php:14
Maintenance & Trust

Caldera Forms styler for Elementor Page Builder Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedDec 3, 2017
PHP min version
Downloads33K

Community Trust

Rating100/100
Number of ratings2
Active installs800
Developer Profile

Caldera Forms styler for Elementor Page Builder Developer Profile

WPDeveloper

46 plugins · 4.0M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
163 days
View full developer profile
Detection Fingerprints

How We Detect Caldera Forms styler for Elementor Page Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/elementor-caldera-forms/assets/css/elementor-caldera-forms.css
Script Paths
/wp-content/plugins/elementor-caldera-forms/assets/js/admin.js/wp-content/plugins/elementor-caldera-forms/assets/vendor/sweetalert2/js/core.js/wp-content/plugins/elementor-caldera-forms/assets/vendor/sweetalert2/js/sweetalert2.min.js
Version Parameters
elementor-caldera-forms/assets/css/elementor-caldera-forms.css?ver=elementor-caldera-forms/assets/js/admin.js?ver=elementor-caldera-forms/assets/vendor/sweetalert2/js/core.js?ver=elementor-caldera-forms/assets/vendor/sweetalert2/js/sweetalert2.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
eael-caldera-forms-admin-csseael-caldera-forms-sweetalert2-csseael-caldera-forms-admin-jseael-caldera-forms-core-jseael-caldera-forms-sweetalert2-jseael-caldera-forms-settingseael-header-bareael-header-left+7 more
HTML Comments
<!-- Caldera Forms styler for Elementor --><!-- Caldera Forms styler for elementor. Design the form visually with elementor. --><!-- Exit if accessed directly --><!-- Upsell -->+10 more
Data Attributes
data-eael-plugin-name="Elementor Caldera Forms Styler"id="eael-caldera-forms-admin-css"id="eael-caldera-forms-sweetalert2-css"id="eael-caldera-forms-admin-js"id="eael-caldera-forms-core-js"id="eael-caldera-forms-sweetalert2-js"+5 more
JS Globals
EAEL_CALDERA_FORMS_URLEAEL_CALDERA_FORMS_PATH
FAQ

Frequently Asked Questions about Caldera Forms styler for Elementor Page Builder