Image Comparison Addon for Elementor Security & Risk Analysis

wordpress.org/plugins/image-comparison-elementor-addon

Image comparison addon for elementor page builder plugin. Install & get image after before element. Drag and Drop the image comparison element and …

90 active installs v1.0.2.3 PHP 5.6+ WP 4.0+ Updated Nov 4, 2025
after-beforebefore-aftercomparisonimageimage-comparison
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Image Comparison Addon for Elementor Safe to Use in 2026?

Generally Safe

Score 100/100

Image Comparison Addon for Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The image-comparison-elementor-addon plugin, version 1.0.2.3, demonstrates a generally strong security posture based on the provided static analysis. All identified AJAX handlers have authorization checks, and there are no unpermissioned REST API routes, shortcodes, or cron events, indicating a well-secured attack surface. The complete absence of raw SQL queries and the use of prepared statements are excellent practices. Furthermore, the presence of nonce checks and capability checks on all identified entry points suggests developers have implemented fundamental security measures to prevent common attacks.

However, there are areas that warrant attention. While the majority of output is properly escaped, 22% of outputs are not, which could lead to Cross-Site Scripting (XSS) vulnerabilities if the unescaped data originates from untrusted user input. The taint analysis revealing two flows with unsanitized paths, even without critical or high severity, is a concern. These flows indicate potential avenues for attackers to manipulate file paths or execute unintended operations, especially if they can control the input to these flows. The plugin also makes four external HTTP requests, which, while not inherently a vulnerability, can introduce risks if the external services are compromised or if the requests themselves are not properly secured against manipulation.

The plugin's vulnerability history is a significant strength, showing no known CVEs. This suggests a history of secure development and diligent patching. The absence of common vulnerability types further reinforces this positive pattern. In conclusion, the plugin is built with several good security practices in place, particularly concerning its entry points and database interactions. The primary weaknesses lie in the unescaped output and the identified unsanitized path flows, which, while not rated critically, represent tangible risks that should be addressed to further harden the plugin's security.

Key Concerns

  • Unescaped output detected
  • Taint flows with unsanitized paths
  • External HTTP requests
Vulnerabilities
None known

Image Comparison Addon for Elementor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Image Comparison Addon for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
45
159 escaped
Nonce Checks
6
Capability Checks
7
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

78% escaped204 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
notification_action (Inc\Classes\Notifications\Notifications.php:48)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Image Comparison Addon for Elementor Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 6

authwp_ajax_jlticel_deactivation_surveyInc\Classes\Feedback.php:29
authwp_ajax_jlticel_notification_actionInc\Classes\Notifications\Notifications.php:40
authwp_ajax_jlticel_subscribeInc\Classes\Notifications\Subscribe.php:26
authwp_ajax_jlticel_allow_collectInc\Classes\Notifications\What_We_Collect.php:27
authwp_ajax_jlticel_recommended_upgrade_pluginLibs\Recommended.php:43
authwp_ajax_jlticel_recommended_activate_pluginLibs\Recommended.php:44
WordPress Hooks 19
actionplugins_loadedclass-image-comparison-elementor-addon.php:52
filteradmin_body_classclass-image-comparison-elementor-addon.php:55
actionelementor/widgets/registerclass-image-comparison-elementor-addon.php:56
actionadmin_noticesclass-image-comparison-elementor-addon.php:71
actionadmin_noticesclass-image-comparison-elementor-addon.php:77
actionadmin_noticesclass-image-comparison-elementor-addon.php:83
actionadmin_enqueue_scriptsInc\Classes\Feedback.php:27
actionadmin_footerInc\Classes\Feedback.php:28
actionadmin_noticesInc\Classes\Notifications\Notifications.php:35
actionjlticel_display_noticeInc\Classes\Notifications\Notifications.php:37
actionjlticel_display_popupInc\Classes\Notifications\Notifications.php:38
actionjlticel_sheet_promo_data_resetInc\Classes\Notifications\Upgrade_Notice.php:26
actionadmin_footerInc\Classes\Pro_Upgrade.php:47
actionwp_dashboard_setupInc\Classes\Pro_Upgrade.php:49
actionwp_enqueue_scriptsLibs\Assets.php:26
actionadmin_enqueue_scriptsLibs\Assets.php:27
filterinstall_plugins_table_api_args_featuredLibs\Featured.php:23
filterplugins_api_resultLibs\Featured.php:33
actionadmin_menuLibs\Recommended.php:42
Maintenance & Trust

Image Comparison Addon for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 4, 2025
PHP min version5.6
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs90
Developer Profile

Image Comparison Addon for Elementor Developer Profile

Liton Arefin

45 plugins · 43K total installs

83
trust score
Avg Security Score
93/100
Avg Patch Time
63 days
View full developer profile
Detection Fingerprints

How We Detect Image Comparison Addon for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/image-comparison-elementor-addon/assets/css/plugin-survey.css

HTML / DOM Fingerprints

CSS Classes
jlticel-deactivate-survey-overlayjlticel-deactivate-survey-modaljlticel-deactivate-survey-headerjlticel-deactivate-infojlticel-deactivate-content-wrapperjlticel-deactivate-form-wrapperjlticel-deactivate-input-wrapperjlticel-deactivate-feedback-dialog-input+3 more
Data Attributes
data-iddata-nonce
JS Globals
JLTICELLOCALIZED
REST Endpoints
/wp-json/jlticel/v1/feedback
FAQ

Frequently Asked Questions about Image Comparison Addon for Elementor