
ExS Widgets Security & Risk Analysis
wordpress.org/plugins/exs-widgetsAdd your posts with various layouts in your theme's widget areas.
Is ExS Widgets Safe to Use in 2026?
Generally Safe
Score 90/100ExS Widgets has a strong security track record. Known vulnerabilities have been patched promptly.
The 'exs-widgets' plugin v0.3.2 exhibits a mixed security posture. On the positive side, the static analysis reveals a generally clean codebase with a significant percentage of properly escaped output and no identified dangerous functions, file operations, external HTTP requests, or SQL queries that aren't prepared. The absence of any identified taint flows is also a strong indicator of good data handling practices within the analyzed code paths.
However, the plugin's vulnerability history presents a significant concern. The presence of one high-severity historical vulnerability, specifically Improper Control of Filename for Include/Require Statement, indicates a past weakness that could allow for remote code execution if exploited. Although currently unpatched vulnerabilities are reported as zero, this historical pattern, coupled with the complete absence of nonce and capability checks and a lack of authentication checks on AJAX handlers and REST API routes, suggests potential avenues for exploitation if specific, unaddressed vulnerabilities were to emerge or if a new attack vector targeting the identified historical vulnerability type were discovered.
In conclusion, while the current static analysis suggests a well-written plugin in terms of code quality and output sanitization, the historical vulnerability and the lack of certain critical security checks (like nonces and capability checks) warrant careful consideration. The plugin has demonstrated a past susceptibility to a severe vulnerability, and its attack surface, though currently reporting zero unprotected entry points, could be vulnerable if specific types of threats emerge that bypass general sanitization and exploit missing authentication or authorization checks.
Key Concerns
- High severity vulnerability in history
- No nonce checks
- No capability checks
- 0 unprotected AJAX handlers
- 0 unprotected REST API routes
- 97% properly escaped output
ExS Widgets Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
ExS Widgets <= 0.3.1 - Authenticated (Contributor+) Local File Inclusion
ExS Widgets Code Analysis
Output Escaping
ExS Widgets Attack Surface
WordPress Hooks 9
Maintenance & Trust
ExS Widgets Maintenance & Trust
Maintenance Signals
Community Trust
ExS Widgets Alternatives
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
One Click Demo Import
one-click-demo-import
Import your demo content, widgets and theme settings with one click. Theme authors! Enable simple theme demo import for your users.
ExS Widgets Developer Profile
5 plugins · 3K total installs
How We Detect ExS Widgets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/exs-widgets/assets/css/exs-widgets.css/wp-content/plugins/exs-widgets/assets/js/media.jsexs-widgets.css?ver=0.0.1media.js?ver=0.0.1HTML / DOM Fingerprints
widget_theme_metadata-widget-idEXS_WIDGETS_PLUGIN_ASSETS_URL