
Include Klaviyo for Elementor pro Security & Risk Analysis
wordpress.org/plugins/include-klaviyo-for-elementor-proKlaviyo's list API integration for Elementor pro form
Is Include Klaviyo for Elementor pro Safe to Use in 2026?
Generally Safe
Score 100/100Include Klaviyo for Elementor pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
This plugin exhibits several concerning security practices despite a clean vulnerability history. The static analysis reveals a significant attack surface, with two AJAX handlers present and critically, both lacking any authentication checks. This means that any unauthenticated user could potentially trigger these handlers, leading to unintended actions within the WordPress site.
While the plugin demonstrates good practices regarding SQL queries (all using prepared statements) and a relatively high percentage of output escaping, the absence of nonces and capability checks on these unprotected AJAX endpoints is a major weakness. The taint analysis, although showing no critical or high severity unsanitized paths, is limited by the lack of broader security checks. The complete absence of known CVEs is positive but should not overshadow the immediate risks identified in the code's entry points.
In conclusion, while the plugin doesn't have a history of publicly disclosed vulnerabilities, the current version presents a clear risk due to its exposed AJAX endpoints. The lack of authentication, nonces, and capability checks on these points is a critical oversight. Developers should prioritize implementing proper authorization and input validation for these AJAX handlers to mitigate potential security threats.
Key Concerns
- Unprotected AJAX handlers without auth checks
- Missing nonce checks on AJAX handlers
- Missing capability checks on AJAX handlers
- File operations detected
- External HTTP requests detected
Include Klaviyo for Elementor pro Security Vulnerabilities
Include Klaviyo for Elementor pro Release Timeline
Include Klaviyo for Elementor pro Code Analysis
Output Escaping
Data Flow Analysis
Include Klaviyo for Elementor pro Attack Surface
AJAX Handlers 2
WordPress Hooks 10
Maintenance & Trust
Include Klaviyo for Elementor pro Maintenance & Trust
Maintenance Signals
Community Trust
Include Klaviyo for Elementor pro Alternatives
Klaviyo
klaviyo
Klaviyo for WooCommerce
Integration for Elementor forms – Sendinblue
integration-for-elementor-forms-sendinblue
Connect your Elementor Pro forms to Sendinblue/Brevo to easily capture and manage contacts from your website.
Add class to Elementor Image
add-class-to-elementor-image
Simple plugin to add custom CSS class to Elementor image.
Product Carousel Slider for Elementor
ecommerce-product-carousel-slider-for-elementor
Product Carousel Slider for Elementor Lets you display your WooCommerce Products as Carousel Slider. You can now display your WooCommerce Products usi …
Gravity Forms Klaviyo Add-On
gf-klaviyo-add-on
Gravity Forms Klaviyo Add-On seamlessly integrates Gravity Forms with Klaviyo, enabling powerful email marketing automation.
Include Klaviyo for Elementor pro Developer Profile
1 plugin · 2K total installs
How We Detect Include Klaviyo for Elementor pro
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/include-klaviyo-for-elementor-pro/klaviyo-elementor-forms.php/wp-content/plugins/include-klaviyo-for-elementor-pro/assets/js/klaviyo-elementor-forms.js/wp-content/plugins/include-klaviyo-for-elementor-pro/assets/css/klaviyo-elementor-forms.css/wp-content/plugins/include-klaviyo-for-elementor-pro/assets/js/klaviyo-elementor-forms.jsinclude-klaviyo-for-elementor-pro/klaviyo-elementor-forms.php?ver=include-klaviyo-for-elementor-pro/assets/js/klaviyo-elementor-forms.js?ver=include-klaviyo-for-elementor-pro/assets/css/klaviyo-elementor-forms.css?ver=HTML / DOM Fingerprints
tho-admin-noticesdata-klaviyo-form-iddismissNotice/wp-json/kvelem/v1/notice