IceCream Elementor Addon Security & Risk Analysis

wordpress.org/plugins/icecream-elementor-addon

IceCream Elementor Addon adds extra widgets to your Elementor page builder.

10 active installs v2.0 PHP 7.4+ WP 5.0+ Updated Oct 30, 2024
addonelementorelementor-addonicecreamicecream-elementor-addon
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is IceCream Elementor Addon Safe to Use in 2026?

Generally Safe

Score 92/100

IceCream Elementor Addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of the "icecream-elementor-addon" v2.0 plugin reveals a generally strong security posture with no identified dangerous functions, SQL injection vulnerabilities, or file operations. The plugin also demonstrates good practices by utilizing prepared statements for all its SQL queries. However, a significant concern lies in the output escaping, where only 53% of the 90 total outputs are properly escaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled correctly before being displayed in the front-end.

The vulnerability history of this plugin is clean, with no recorded CVEs. This absence of historical vulnerabilities, coupled with the lack of critical taint analysis findings, suggests that the developers may have a good understanding of secure coding practices. However, the low percentage of properly escaped output remains a notable weakness that could be exploited despite the absence of historical issues. While the plugin exhibits strengths in areas like SQL handling and a clean vulnerability record, the potential for XSS due to insufficient output escaping warrants careful attention and remediation.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

IceCream Elementor Addon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

IceCream Elementor Addon Release Timeline

v2.0Current
v1.2.0
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

IceCream Elementor Addon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
42
48 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

53% escaped90 total outputs
Attack Surface

IceCream Elementor Addon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuadmin\admin.php:11
actionadmin_enqueue_scriptsadmin\admin.php:12
actionelementor/widgets/registericecreameaddon.php:42
actionelementor/elements/categories_registeredicecreameaddon.php:43
Maintenance & Trust

IceCream Elementor Addon Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 30, 2024
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

IceCream Elementor Addon Developer Profile

Reza Masoumpour

3 plugins · 10 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect IceCream Elementor Addon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/icecream-elementor-addon/admin/admin.css
Version Parameters
icecream-elementor-addon/admin/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
icecream_cat
FAQ

Frequently Asked Questions about IceCream Elementor Addon