
Eleshop Security & Risk Analysis
wordpress.org/plugins/eleshopBest Elementor Addon for WooCommerce.
Is Eleshop Safe to Use in 2026?
Generally Safe
Score 85/100Eleshop has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The eleshop plugin v1.0.4.1 exhibits a generally strong security posture based on the provided static analysis. The complete absence of identified entry points such as AJAX handlers, REST API routes, shortcodes, and cron events is a significant strength, drastically reducing the potential attack surface. Furthermore, the fact that all observed SQL queries utilize prepared statements is excellent practice, mitigating risks of SQL injection. The presence of capability checks, even if limited, suggests an awareness of access control mechanisms.
However, a notable concern arises from the low percentage of properly escaped output (20%). This indicates that a significant portion of data output by the plugin might be vulnerable to Cross-Site Scripting (XSS) attacks if user-controlled input is not adequately sanitized before being rendered. The lack of detected taint flows is positive, but it's important to remember that static analysis might not catch all complex injection vulnerabilities. The plugin's vulnerability history being entirely clean is a very good sign, suggesting developers are either diligent with security or the plugin hasn't been a target. The bundled Freemius library should be monitored for potential vulnerabilities in its own right, although no specific version issues were flagged here.
In conclusion, while the plugin has commendable strengths in limiting its attack surface and securing database interactions, the unescaped output represents a concrete area of concern that requires attention to prevent XSS vulnerabilities. The clean vulnerability history is a strong positive, but ongoing vigilance, especially regarding output sanitization and library updates, is recommended.
Key Concerns
- Low percentage of properly escaped output
- Bundled Freemius library v1.0
Eleshop Security Vulnerabilities
Eleshop Code Analysis
Bundled Libraries
Output Escaping
Eleshop Attack Surface
WordPress Hooks 18
Maintenance & Trust
Eleshop Maintenance & Trust
Maintenance Signals
Community Trust
Eleshop Alternatives
Widgets for WooCommerce Products on Elementor
woo-products-widgets-for-elementor
Woo Products widget is a plugin that allows adding WooCommerce Products and Categories into stylish grid and listing layouts to the pages built with E …
All-in-One Addons for Elementor – WidgetKit
widgetkit-for-elementor
Build stunning websites with Elementor using premium widgets for WooCommerce, LearnDash & LearnPress. Free creative, content & dynamic widget pack.
ShopPress – Shop Builder for Elementor and WooCommerce
shop-press
ShopPress is a shop builder that works with WooCommerce and Elementor. Design store pages (shop, product, cart, checkout, my account) and product loop …
Shopready – Elementor addons for WooCommerce Page Builder
shopready-elementor-addon
ShopReady - WooCommerce Builder Elementor Addon. Available functions/features are WooCommerce Template Builder (Basic), WooCommerce Product Grid, WooC …
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Eleshop Developer Profile
45 plugins · 43K total installs
How We Detect Eleshop
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/eleshop/assets/css/eleshop-admin.css/wp-content/plugins/eleshop/assets/js/manifest.js/wp-content/plugins/eleshop/assets/js/vendor.js/wp-content/plugins/eleshop/assets/js/eleshop-admin.js/wp-content/plugins/eleshop/libs/freemius/start.phpeleshop/assets/js/manifest.js?ver=eleshop/assets/js/vendor.js?ver=eleshop/assets/js/eleshop-admin.js?ver=HTML / DOM Fingerprints
eleshop-badgeeleshop-wrapeleshop-admin-appeleshopLocalize/wp-json/eleshop/v1/settings<div class="eleshop-wrap"><div class="container"><div id="eleshop-admin-app"></div></div></div>