
LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor Security & Risk Analysis
wordpress.org/plugins/include-lottie-animation-for-elementorCreative layout to your site with smaller json file using Lottie animations.
Is LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor Safe to Use in 2026?
Generally Safe
Score 99/100LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.
The "include-lottie-animation-for-elementor" plugin v1.10.24 presents a mixed security posture. While it demonstrates good practices in areas like SQL query preparation and a lack of dangerous functions or file operations, significant concerns arise from its attack surface and vulnerability history. The presence of an unprotected AJAX handler is a direct entry point that could be exploited if not properly validated server-side, especially given the potential for cross-site scripting (XSS) as indicated by past vulnerabilities.
The static analysis reveals a single unprotected AJAX handler, which is a critical weakness. Although no direct taint flows were identified in this specific analysis, the historical vulnerability pattern of XSS suggests that improper handling of user input within AJAX actions could lead to such issues. The plugin's output escaping is also a concern, with a significant portion not being properly sanitized, further increasing the risk of XSS if malicious input reaches these points.
Despite the absence of currently unpatched CVEs and the use of prepared statements for SQL, the single unprotected AJAX entry point and the history of XSS vulnerabilities indicate a need for heightened vigilance. The plugin's strengths lie in its avoidance of severe code signals like raw SQL or dangerous functions, but these are overshadowed by the direct exposure of an AJAX handler and past exploitability. Overall, while not critically flawed in every aspect, the plugin requires careful attention to its input validation and output sanitization, particularly concerning the identified AJAX endpoint.
Key Concerns
- Unprotected AJAX handler
- Insufficient output escaping
- Historical XSS vulnerability
LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor <= 1.10.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor Code Analysis
Output Escaping
LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor Alternatives
Animentor – Lottie & Bodymovin for Elementor
animentor-lottie-bodymovin-elementor
An Elementor extension that adds a widget for Lottie animations.
Animation Addons for Elementor – GSAP Motion & Website Templates
animation-addons-for-elementor
GSAP Animation Powered Elementor Addon & Motion Hub with 300+ Website Templates, Advanced Extensions, and 100+ Elementor Widgets
LottieFiles
lottiefiles
LottieFiles for WordPress is the easiest way to add Lottie animations to your WordPress website using the Gutenberg editor.
Marvy – Background Animations for Elementor
marvy-animation-addons-for-elementor-lite
Marvy is the ultimate animation add-on for Elementor. Bring your pages to life with next-generation animation effects and seamless Elementor integrati …
HoverMagix – Elementor Addon
hovermagix-elementor-addon
Add beautiful image hover effects with captions and animations using Elementor. Includes scale, direction, and layered effects.
LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor Developer Profile
6 plugins · 5K total installs
How We Detect LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/include-lottie-animation-for-elementor/assets/css/jbafe_css.min.css/wp-content/plugins/include-lottie-animation-for-elementor/assets/js/extra/lottie.min.js/wp-content/plugins/include-lottie-animation-for-elementor/assets/js/main/jbafe_script.min.js/wp-content/plugins/include-lottie-animation-for-elementor/assets/js/admin/jbafe_script_note.js/wp-content/plugins/include-lottie-animation-for-elementor/assets/js/extra/lottie.min.js/wp-content/plugins/include-lottie-animation-for-elementor/assets/js/main/jbafe_script.min.js/wp-content/plugins/include-lottie-animation-for-elementor/assets/js/admin/jbafe_script_note.js/wp-content/plugins/include-lottie-animation-for-elementor/assets/js/extra/lottie.min.js?ver=/wp-content/plugins/include-lottie-animation-for-elementor/assets/js/main/jbafe_script.min.js?ver=/wp-content/plugins/include-lottie-animation-for-elementor/assets/css/jbafe_css.min.css?ver=/wp-content/plugins/include-lottie-animation-for-elementor/assets/js/admin/jbafe_script_note.js?ver=HTML / DOM Fingerprints
jbafe-noticedata-elementor-device-modeJBAFE_VERSIONJBAFE_PATHJBAFE_URL