
Envo's Templates & Widgets for Elementor and WooCommerce Security & Risk Analysis
wordpress.org/plugins/envo-elementor-for-woocommerceAddon with WooCommerce Templates & Widgets for Elementor
Is Envo's Templates & Widgets for Elementor and WooCommerce Safe to Use in 2026?
Generally Safe
Score 97/100Envo's Templates & Widgets for Elementor and WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The envo-elementor-for-woocommerce plugin v1.4.25 presents a mixed security posture. On the positive side, the plugin utilizes prepared statements for its SQL queries, and the majority of output is properly escaped. It also demonstrates a good number of capability checks and some nonce checks.
However, there are significant concerns stemming from the attack surface. With 9 AJAX handlers, 5 of which lack authentication checks, there's a substantial potential for unauthorized actions or information disclosure. The taint analysis, while not showing critical or high severity issues, did reveal 4 flows with unsanitized paths, which, combined with the unprotected AJAX endpoints, could potentially lead to vulnerabilities if exploited. The file operations and external HTTP requests also warrant careful consideration as they can be vectors for further compromise.
The vulnerability history of this plugin is concerning, with 6 known medium-severity CVEs in the past, commonly related to Cross-site Scripting (XSS), Cross-Site Request Forgery (CSRF), and Improper Access Control. Although there are currently no unpatched CVEs, this history indicates a pattern of past security weaknesses that could resurface or be related to the issues found in the static analysis. The plugin has a history of vulnerabilities that require thorough review, especially regarding input handling and access control.
Key Concerns
- Large attack surface without auth checks (AJAX)
- Flows with unsanitized paths
- High percentage of output not properly escaped
- History of 6 medium CVEs
- File operations present
- External HTTP requests present
Envo's Templates & Widgets for Elementor and WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
Envo's Elementor Templates & Widgets for WooCommerce <= 1.4.19 - Authenticated (Contributor+) Stored Cross-Site Scripting
Envo's Elementor Templates & Widgets for WooCommerce <= 1.4.16 - Authenticated (Author+) Stored Cross-Site Scripting
Envo's Elementor Templates & Widgets for WooCommerce <= 1.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
Envo's Elementor Templates & Widgets for WooCommerce <= 1.4.4 - Cross-Site Request Forgery via ajax_theme_activation
Envo's Elementor Templates & Widgets for WooCommerce <= 1.4.4 - Missing Authorization via templates_ajax_request
Envo's Elementor Templates & Widgets for WooCommerce <= 1.4.4 - Cross-Site Request Forgery via ajax_plugin_activation
Envo's Templates & Widgets for Elementor and WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Envo's Templates & Widgets for Elementor and WooCommerce Attack Surface
AJAX Handlers 9
WordPress Hooks 29
Maintenance & Trust
Envo's Templates & Widgets for Elementor and WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Envo's Templates & Widgets for Elementor and WooCommerce Alternatives
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
RTMKit
rometheme-for-elementor
All-in-one toolkit for Elementor: advanced addons, theme builder, forms, icons & templates to build stunning sites fast and easy.
Bosa Elementor Addons and Templates for WooCommerce
bosa-elementor-for-woocommerce
Elementor Addon with widgets and templates for WooCommerce.
Spexo Addons for Elementor – Elementor Widgets, WooCommerce Builder, Mega Menu and Starter Templates for Elementor
sastra-essential-addons-for-elementor
Advanced Elementor addons plugin with widgets, WooCommerce builders, mega menu, template kits and extensions for faster WordPress website design.
Turbo Addons Elementor
turbo-addons-elementor
Turbo Addons for Elementor offers advanced widgets to enhance Elementor, helping you create professional, interactive websites easily and quickly.
Envo's Templates & Widgets for Elementor and WooCommerce Developer Profile
16 plugins · 90K total installs
How We Detect Envo's Templates & Widgets for Elementor and WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/envo-elementor-for-woocommerce/includes/admin/assets/lib/css/selectric.css/wp-content/plugins/envo-elementor-for-woocommerce/includes/admin/assets/css/tmp-style.css/wp-content/plugins/envo-elementor-for-woocommerce/includes/admin/assets/lib/js/jquery.selectric.min.js/wp-content/plugins/envo-elementor-for-woocommerce/includes/admin/assets/lib/js/ScrollMagic.min.js/wp-content/plugins/envo-elementor-for-woocommerce/includes/admin/assets/js/template_library_manager.js/wp-content/plugins/envo-elementor-for-woocommerce/includes/admin/assets/js/install_manager.js/wp-content/plugins/envo-elementor-for-woocommerce/includes/admin/assets/images/loading.gif/wp-content/plugins/envo-elementor-for-woocommerce/includes/admin/img//wp-content/plugins/envo-elementor-for-woocommerce/includes/admin/assets/lib/js/jquery.selectric.min.js/wp-content/plugins/envo-elementor-for-woocommerce/includes/admin/assets/lib/js/ScrollMagic.min.js/wp-content/plugins/envo-elementor-for-woocommerce/includes/admin/assets/js/template_library_manager.js/wp-content/plugins/envo-elementor-for-woocommerce/includes/admin/assets/js/install_manager.jsver=1.4.25HTML / DOM Fingerprints
etww-admin-settings-pagedata-etww-data-nonceetww_addonsWLTM