
Happy Addons for Elementor Security & Risk Analysis
wordpress.org/plugins/happy-elementor-addonsHappyAddons for Elementor-Get Header Footer, Single Post, Archive Page, Megamenu, Slider Builder & 143 Elementor Widgets.
Is Happy Addons for Elementor Safe to Use in 2026?
Generally Safe
Score 95/100Happy Addons for Elementor has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "happy-elementor-addons" plugin, version 3.21.1, presents a mixed security posture. While the plugin demonstrates good practices such as 100% use of prepared statements for SQL queries and a significant percentage of properly escaped output, there are considerable concerns. The high number of unprotected AJAX handlers (14 out of 14) creates a substantial attack surface, making it vulnerable to unauthorized actions if proper authorization checks are bypassed. Although no critical or high severity taint flows were identified in this specific analysis, the presence of two flows with unsanitized paths warrants attention. The plugin's historical vulnerability data is a major red flag, with 40 known medium severity CVEs, including types like Authorization Bypass, SQL Injection, and XSS. The fact that the last vulnerability was recorded in the future (2026-03-10) is a data anomaly but the sheer volume and nature of past vulnerabilities suggest a recurring pattern of security weaknesses that require diligent and timely patching.
Despite the good practices in SQL handling and output escaping, the significant number of unprotected AJAX entry points is a critical weakness that attackers could exploit. The extensive history of medium-severity vulnerabilities, encompassing critical attack vectors, indicates a potential systemic issue with how the plugin handles security, even if recent versions don't show critical flaws in this specific analysis. The presence of bundled libraries like Select2 also adds a dependency that could introduce vulnerabilities if not managed carefully. While the current version appears to have addressed immediate critical threats based on this static analysis, the historical context and the large unprotected attack surface suggest a moderate to high-risk profile.
In conclusion, "happy-elementor-addons" v3.21.1 has strengths in its database query and output handling. However, the large number of unprotected AJAX endpoints and the plugin's history of numerous medium-severity vulnerabilities, including common web attack types, pose significant risks. Users should be aware of the potential for exploitation due to the unprotected entry points and the historical pattern of security issues. Continued vigilance and prompt updates are crucial.
Key Concerns
- 14 unprotected AJAX handlers
- 2 unsanitized path flows (taint analysis)
- 40 total known CVEs (medium severity)
- Bundled library (Select2)
Happy Addons for Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
42 total CVEs
Happy Addons for Elementor <= 3.20.8 - Unauthenticated Information Exposure
Happy Addons for Elementor <= 3.21.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Post Duplication via 'post_id' Parameter
Happy Addons for Elementor <= 3.21.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Stored Cross-Site Scripting via Template Conditions
Happy Addons for Elementor <= 3.20.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via '_elementor_data' Meta Field
Happy Addons for Elementor <= 3.20.4 - Authenticated (Contributor+) SQL Injection
Happy Addons for Elementor <= 3.20.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS
Happy Addons for Elementor <= 3.20.3 - Missing Authorization
Happy Addons for Elementor <= 3.16.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Happy Addons for Elementor <= 3.15.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Happy Addons for Elementor <= 3.12.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison
Happy Addons for Elementor <= 3.12.3 - Missing Authorization
Happy Addons for Elementor <= 3.12.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Happy Addons for Elementor <= 3.12.2 - Authenticated (Contributor+) Sensitive Information Exposure
Happy Addons for Elementor <= 3.11.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via PDF View Widget
Happy Addons for Elementor <= 3.11.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gradient Heading Widget
Happy Addons for Elementor <= 3.10.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Navigation Widget
Happy Addons for Elementor <= 3.10.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion
Happy Addons for Elementor <= 3.10.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via _id Parameter
Happy Addons for Elementor <= 3.10.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
Happy Addons for Elementor Authenticated (Contributor+) Stored-XSS <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar Widget
Happy Addons for Elementor <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Stack Group Widget
Happy Addons for Elementor <= 3.10.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Calendly Widget
Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Happy Addons for Elementor <= 3.10.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Stack Group, Photo Stack, & Horizontal Timeline
Happy Addons for Elementor <= 3.10.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags
Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via title_tag
Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title HTML Tag
Happy Addons for Elementor <= 3.10.4 - Incorrect Authorization to Information Exposure
Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Calendy
Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Page Title HTML Tag
Happy Addons for Elementor <= 3.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Photo Stack Widget
Happy Addons for Elementor <= 3.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Archive Title Widget
Happy Addons for Elementor <= 3.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Author Meta Widget
Happy Addons for Elementor <= 3.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Happy Addons for Elementor <= 3.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Happy Addons for Elementor <= 3.10.1 - Missing Authorization via add_row_actions
Happy Elementor Addons <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Happy Addons for Elementor <= 3.9.1.1 - Reflected Cross-Site Scripting
Happy Addons for Elementor <= 3.9.1.1 - Server Side Request Forgery
Happy Addons for Elementor <= 3.8.2 - Cross-Site Request Forgery via handle_optin_optout()
Appsero <= 1.2.1 - Missing Authorization
Happy Addons for Elementor <= 2.23.0 & Pro Version < 1.17.0 - Stored Cross-Site Scripting
Happy Addons for Elementor Release Timeline
Happy Addons for Elementor Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Happy Addons for Elementor Attack Surface
AJAX Handlers 14
REST API Routes 7
WordPress Hooks 160
Maintenance & Trust
Happy Addons for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
Happy Addons for Elementor Alternatives
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
premium-addons-for-elementor
Elementor Carousel, Mega Menu, Posts List/Slider, Media Gallery, WooCommerce Widgets, Display Conditions, Premade Templates & more.
Royal Addons for Elementor – Addons and Templates Kit for Elementor
royal-elementor-addons
Elementor templates, Header footer builder, Elementor Post Grid, Woocommerce Grid builder, Slider, Forms, Gallery, Nav menu addons, Elementor widgets.
HT Mega Addons for Elementor – Elementor Widgets & Template Builder
ht-mega-for-elementor
Elementor addon offering 135+ widgets — Mega Menu, Ready Templates, Page Builder, Slider, Gallery, Post Grid, AI Writer & more.
Happy Addons for Elementor Developer Profile
3 plugins · 400K total installs
How We Detect Happy Addons for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/happy-elementor-addons/assets/css/frontend.css/wp-content/plugins/happy-elementor-addons/assets/js/frontend.js/wp-content/plugins/happy-elementor-addons/assets/js/wow.min.js/wp-content/plugins/happy-elementor-addons/assets/js/particles.min.js/wp-content/plugins/happy-elementor-addons/assets/js/wow.js/wp-content/plugins/happy-elementor-addons/assets/js/frontend.js/wp-content/plugins/happy-elementor-addons/assets/js/wow.min.js/wp-content/plugins/happy-elementor-addons/assets/js/particles.min.js/wp-content/plugins/happy-elementor-addons/assets/js/wow.jshappy-elementor-addons/assets/css/frontend.css?ver=happy-elementor-addons/assets/js/frontend.js?ver=happy-elementor-addons/assets/js/wow.min.js?ver=happy-elementor-addons/assets/js/particles.min.js?ver=happy-elementor-addons/assets/js/wow.js?ver=HTML / DOM Fingerprints
ha-inline-editordata-wow-delaydata-wow-durationdata-wow-offsetdata-wow-iterationhappyAddonsFrontend