Flux Elementor Addons Security & Risk Analysis

wordpress.org/plugins/flux-addons

Flux addons is the new free widget library for Elementor page builder users to design the business website more user-friendly.

10 active installs v1.0.0 PHP 5.4+ WP 4.7+ Updated Mar 12, 2020
elementorelementor-addonselementor-widgetelementsessential-widget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Flux Elementor Addons Safe to Use in 2026?

Generally Safe

Score 85/100

Flux Elementor Addons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The static analysis of flux-addons v1.0.0 reveals a generally positive security posture. The absence of any detectable attack surface, including AJAX handlers, REST API routes, shortcodes, and cron events, significantly limits potential entry points for attackers. Furthermore, the code demonstrates good practices by utilizing prepared statements for all SQL queries and avoiding file operations and external HTTP requests. This suggests a deliberate effort to minimize common web application vulnerabilities.

However, a notable concern arises from the output escaping analysis, where only 54% of outputs are properly escaped. This indicates a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being displayed. The complete absence of nonce checks and capability checks, while perhaps justifiable given the limited attack surface, also represents missed opportunities for enhancing security, especially if functionality were to be added in the future. The vulnerability history showing zero CVEs is a strong positive, suggesting a mature and well-maintained codebase, or at least one that has not historically attracted significant security attention.

In conclusion, flux-addons v1.0.0 exhibits strengths in its minimal attack surface and secure handling of database interactions. The primary weakness lies in the incomplete output escaping, which poses an XSS risk. The lack of historical vulnerabilities is encouraging, but the current code has room for improvement in output sanitization and the implementation of basic security checks like nonces and capability checks to ensure a more robust security foundation.

Key Concerns

  • Insufficient output escaping detected
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Flux Elementor Addons Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Flux Elementor Addons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
36
42 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

54% escaped78 total outputs
Attack Surface

Flux Elementor Addons Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actioninitbase.php:73
actionplugins_loadedbase.php:74
actionadmin_noticesbase.php:111
actionadmin_noticesbase.php:117
actionadmin_noticesbase.php:123
actionelementor/frontend/after_enqueue_stylesincludes\Elements.php:25
actionelementor/frontend/after_register_scriptsincludes\Elements.php:28
actionelementor/widgets/widgets_registeredincludes\Elements.php:31
actionelementor/initincludes\Elements.php:36
filterelementor/utils/get_placeholder_image_srcincludes\Elements.php:39
actionelementor/element/after_section_endincludes\Extenstion\Transform.php:19
actionelementor/element/after_section_endincludes\Extenstion\Transform.php:20
actionelementor/element/after_section_endincludes\Extenstion\Transform.php:21
Maintenance & Trust

Flux Elementor Addons Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedMar 12, 2020
PHP min version5.4
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Flux Elementor Addons Developer Profile

Flux Theme

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Flux Elementor Addons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/flux-addons/assets/css/advance-heading.css/wp-content/plugins/flux-addons/assets/css/funfact.css/wp-content/plugins/flux-addons/assets/css/counter.css/wp-content/plugins/flux-addons/assets/css/vendor/counterup.min.css/wp-content/plugins/flux-addons/assets/css/vendor/waypoints.min.css/wp-content/plugins/flux-addons/assets/css/image-slide-show.css/wp-content/plugins/flux-addons/assets/css/icon-box.css/wp-content/plugins/flux-addons/assets/css/logo-carousel.css+15 more
Script Paths
/wp-content/plugins/flux-addons/assets/js/advance-heading.js/wp-content/plugins/flux-addons/assets/js/counter.js/wp-content/plugins/flux-addons/assets/js/vendor/counterup.min.js/wp-content/plugins/flux-addons/assets/js/vendor/waypoints.min.js/wp-content/plugins/flux-addons/assets/js/images-slide-show.js/wp-content/plugins/flux-addons/assets/js/logo-carousel.js+4 more
Version Parameters
flux-addons/style.css?ver=flux-addons/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
flux-advance-headingflux-funfact-wrapperflux-img-slideshow-wrapperflux-icon-box-wrapperflux-logo-carousel-wrapperflux-pricing-table-wrapperflux-team-wrapperflux-testimonial-wrapper+1 more
Data Attributes
data-widget_typedata-element_typedata-id
JS Globals
elementorFLUX_ADDONS_ASSETS
FAQ

Frequently Asked Questions about Flux Elementor Addons