
EleSpare – News, Magazine and Blog Addons for Elementor Security & Risk Analysis
wordpress.org/plugins/elespareEleSpare provides pre-designed templates, header/footer builders, and various post layouts for creating stunning news, magazine, and blog sites with E …
Is EleSpare – News, Magazine and Blog Addons for Elementor Safe to Use in 2026?
Generally Safe
Score 99/100EleSpare – News, Magazine and Blog Addons for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.
The "elespare" plugin v3.3.10 exhibits a mixed security posture. On one hand, the static analysis reveals positive practices such as 100% use of prepared statements for SQL queries, a high rate of proper output escaping (97%), and robust use of nonce and capability checks. However, there are significant concerns regarding the attack surface. Specifically, 2 out of 6 entry points, consisting of REST API routes, lack permission callbacks, making them potentially accessible to unauthorized users. The taint analysis shows no unsanitized paths, which is a strong positive indicator. The vulnerability history reveals a pattern of past vulnerabilities, including Cross-site Scripting and Missing Authorization, with two medium-severity CVEs historically. While currently unpatched vulnerabilities are zero, the past incidents, especially those related to authorization, align with the observed unprotected REST API routes, highlighting a persistent area of risk that needs careful monitoring and remediation.
Despite the absence of critical findings in the current static and taint analysis and the lack of currently unpatched vulnerabilities, the presence of unprotected REST API endpoints is a direct security concern. This, coupled with the historical pattern of authorization and XSS vulnerabilities, suggests that the plugin, while improving, has had past weaknesses in input validation and access control. The overall security is decent due to good SQL and output handling, but the unprotected entry points represent a clear and present risk. The bundled Freemius library, while version 1.0, is not flagged as outdated by the provided data, but should be a consideration for future checks if more detailed information were available. The conclusion is that the plugin is generally well-coded but has specific, exploitable weaknesses in its access control mechanisms for its REST API.
Key Concerns
- REST API routes without permission callbacks
- Historically vulnerable to XSS and Missing Authorization
EleSpare – News, Magazine and Blog Addons for Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Elespare – Blog, Magazine and Newspaper Addons for Elementor with Templates, Widgets, Kits, and Header/Footer Builder. One Click Import: No Coding Required! <= 3.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Horizontal Nav Menu Widget
Elespare – Build Your Blog, News & Magazine Websites with Expert-Designed Template Kits. One Click Import: No Coding Skills Required! <= 2.1.2 - Missing Authorization to Subscriber+ Arbitrary Post Creation
EleSpare – News, Magazine and Blog Addons for Elementor Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
EleSpare – News, Magazine and Blog Addons for Elementor Attack Surface
AJAX Handlers 2
REST API Routes 2
Shortcodes 2
WordPress Hooks 48
Maintenance & Trust
EleSpare – News, Magazine and Blog Addons for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
EleSpare – News, Magazine and Blog Addons for Elementor Alternatives
Unlimited Elements For Elementor
unlimited-elements-for-elementor
Elementor all-in-one addons pack with the best widgets for Elementor, offering 100+ free widgets, templates, and tools to create stunning websites!
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
the-plus-addons-for-elementor-page-builder
Best Addons for Elementor with 120+ Elementor FREE & Pro Widgets & 1000+ Elementor Templates with Mega Menu, Post Grid, Header Footer, WooCommerce
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits
master-addons
55+ Elementor widgets, 20+ extensions, Theme Builder, Popup Builder, Widget Builder & Template Kits — build any site without code.
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder
king-addons
Elementor addons: Elementor widgets, Elementor templates, 80+ widgets, 4 000+ templates and sections, Mega Menu, Popup Builder, WooCommerce, AI tools.
Responsive Addons for Elementor – Free Elementor Addons, Kits and Elementor Templates
responsive-addons-for-elementor
Free Elementor addons plugin with 80+ widgets, 5+ extensions, Theme builder, 250+ Elementor templates, 500+ modern UI sections for Elementor websites.
EleSpare – News, Magazine and Blog Addons for Elementor Developer Profile
1 plugin · 10K total installs
How We Detect EleSpare – News, Magazine and Blog Addons for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/elespare/dist/elespare.style.build.min.csselespare-posts-gridHTML / DOM Fingerprints
elespare-pro-link