Fancy Elementor Flipbox Security & Risk Analysis

wordpress.org/plugins/fancy-elementor-flipbox

Create flip box and 6 more effects with front and back side options

5K active installs v2.6.1 PHP 7.4+ WP 4.0+ Updated May 11, 2025
elementorelementor-addonelementor-widgetflip-boxhover-effects
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 29, 2024
Safety Verdict

Is Fancy Elementor Flipbox Safe to Use in 2026?

Generally Safe

Score 99/100

Fancy Elementor Flipbox has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 29, 2024Updated 10mo ago
Risk Assessment

The static analysis of the "fancy-elementor-flipbox" plugin version 2.6.1 reveals a generally strong security posture. The plugin demonstrates good development practices by having no identified dangerous functions, no raw SQL queries (all are prepared), and 100% of output is properly escaped. Furthermore, there are no file operations or external HTTP requests, and the plugin does not bundle any libraries, which reduces the attack surface associated with third-party code.

However, the plugin's vulnerability history is a significant concern. It has a total of one known CVE, which is a medium-severity Cross-Site Scripting (XSS) vulnerability that was recently patched. While it's positive that it's currently unpatched, the existence of a medium-severity XSS vulnerability, especially one that was recently discovered and patched, indicates a potential weakness in input sanitization or output encoding, despite the static analysis reporting 100% output escaping. The lack of any detected taint flows in the static analysis might suggest that the vulnerability was in a specific, less commonly triggered code path, or that the static analysis tools were unable to fully trace the flow in this particular instance.

In conclusion, the plugin exhibits commendable security practices in its current code, with a minimal attack surface and robust output handling. The primary weakness lies in its past vulnerability, specifically the recent medium-severity XSS. This suggests that while the plugin's developers are responsive to security issues, there's a need for continued vigilance and potentially more comprehensive security testing to prevent future occurrences of similar vulnerabilities.

Key Concerns

  • Previously patched medium severity XSS vulnerability
  • No nonce checks identified
Vulnerabilities
1

Fancy Elementor Flipbox Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-2349medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Fancy Elementor Flipbox <= 2.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Elementor Flipbox Widget

Apr 29, 2024 Patched in 2.5.2 (23d)
Code Analysis
Analyzed Mar 16, 2026

Fancy Elementor Flipbox Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
9 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped9 total outputs
Attack Surface

Fancy Elementor Flipbox Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_noticesfancy-elementor-flipbox.php:31
actionadmin_noticesfancy-elementor-flipbox.php:38
actionplugins_loadedfancy-elementor-flipbox.php:45
filterplugin_row_metafancy-elementor-flipbox.php:99
actionelementor/widgets/widgets_registeredplugin.php:36
actionelementor/frontend/after_register_scriptsplugin.php:37
actionelementor/frontend/after_enqueue_stylesplugin.php:42
Maintenance & Trust

Fancy Elementor Flipbox Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 11, 2025
PHP min version7.4
Downloads52K

Community Trust

Rating100/100
Number of ratings4
Active installs5K
Developer Profile

Fancy Elementor Flipbox Developer Profile

Hossein Hashemi

2 plugins · 5K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
23 days
View full developer profile
Detection Fingerprints

How We Detect Fancy Elementor Flipbox

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fancy-elementor-flipbox/assets/css/fancy-elementor-flipbox.css
Script Paths
/wp-content/plugins/fancy-elementor-flipbox/assets/js/fancy-elementor-flipbox.js

HTML / DOM Fingerprints

CSS Classes
fancy-elementor-flipbox-wrapper
Data Attributes
data-settings
JS Globals
fancyElementorFlipbox
FAQ

Frequently Asked Questions about Fancy Elementor Flipbox