LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor Security & Risk Analysis

wordpress.org/plugins/include-lottie-animation-for-elementor

Creative layout to your site with smaller json file using Lottie animations.

3K active installs v1.10.24 PHP 5.6+ WP 5.7.0+ Updated Feb 1, 2026
animationbodymovinelementorelementor-addonlottie
99
A · Safe
CVEs total1
Unpatched0
Last CVEMay 23, 2024
Safety Verdict

Is LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor Safe to Use in 2026?

Generally Safe

Score 99/100

LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: May 23, 2024Updated 2mo ago
Risk Assessment

The "include-lottie-animation-for-elementor" plugin v1.10.24 presents a mixed security posture. While it demonstrates good practices in areas like SQL query preparation and a lack of dangerous functions or file operations, significant concerns arise from its attack surface and vulnerability history. The presence of an unprotected AJAX handler is a direct entry point that could be exploited if not properly validated server-side, especially given the potential for cross-site scripting (XSS) as indicated by past vulnerabilities.

The static analysis reveals a single unprotected AJAX handler, which is a critical weakness. Although no direct taint flows were identified in this specific analysis, the historical vulnerability pattern of XSS suggests that improper handling of user input within AJAX actions could lead to such issues. The plugin's output escaping is also a concern, with a significant portion not being properly sanitized, further increasing the risk of XSS if malicious input reaches these points.

Despite the absence of currently unpatched CVEs and the use of prepared statements for SQL, the single unprotected AJAX entry point and the history of XSS vulnerabilities indicate a need for heightened vigilance. The plugin's strengths lie in its avoidance of severe code signals like raw SQL or dangerous functions, but these are overshadowed by the direct exposure of an AJAX handler and past exploitability. Overall, while not critically flawed in every aspect, the plugin requires careful attention to its input validation and output sanitization, particularly concerning the identified AJAX endpoint.

Key Concerns

  • Unprotected AJAX handler
  • Insufficient output escaping
  • Historical XSS vulnerability
Vulnerabilities
1

LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-5060medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor <= 1.10.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 23, 2024 Patched in 1.10.10 (1d)
Code Analysis
Analyzed Mar 16, 2026

LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
15 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

68% escaped22 total outputs
Attack Surface
1 unprotected

LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_jbafe_top_noticejson-based-animation-for-elementor.php:81
WordPress Hooks 9
actionplugins_loadedjson-based-animation-for-elementor.php:38
actionadmin_noticesjson-based-animation-for-elementor.php:45
actionelementor/initjson-based-animation-for-elementor.php:49
actionelementor/frontend/after_enqueue_stylesjson-based-animation-for-elementor.php:50
actionelementor/widgets/registerjson-based-animation-for-elementor.php:51
actionadmin_initjson-based-animation-for-elementor.php:53
actionadmin_enqueue_scriptsjson-based-animation-for-elementor.php:54
actioninitjson-based-animation-for-elementor.php:56
actionadmin_noticesjson-based-animation-for-elementor.php:80
Maintenance & Trust

LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 1, 2026
PHP min version5.6
Downloads49K

Community Trust

Rating100/100
Number of ratings8
Active installs3K
Developer Profile

LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor Developer Profile

KAP ASIAs

6 plugins · 5K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/include-lottie-animation-for-elementor/assets/css/jbafe_css.min.css/wp-content/plugins/include-lottie-animation-for-elementor/assets/js/extra/lottie.min.js/wp-content/plugins/include-lottie-animation-for-elementor/assets/js/main/jbafe_script.min.js/wp-content/plugins/include-lottie-animation-for-elementor/assets/js/admin/jbafe_script_note.js
Script Paths
/wp-content/plugins/include-lottie-animation-for-elementor/assets/js/extra/lottie.min.js/wp-content/plugins/include-lottie-animation-for-elementor/assets/js/main/jbafe_script.min.js/wp-content/plugins/include-lottie-animation-for-elementor/assets/js/admin/jbafe_script_note.js
Version Parameters
/wp-content/plugins/include-lottie-animation-for-elementor/assets/js/extra/lottie.min.js?ver=/wp-content/plugins/include-lottie-animation-for-elementor/assets/js/main/jbafe_script.min.js?ver=/wp-content/plugins/include-lottie-animation-for-elementor/assets/css/jbafe_css.min.css?ver=/wp-content/plugins/include-lottie-animation-for-elementor/assets/js/admin/jbafe_script_note.js?ver=

HTML / DOM Fingerprints

CSS Classes
jbafe-notice
Data Attributes
data-elementor-device-mode
JS Globals
JBAFE_VERSIONJBAFE_PATHJBAFE_URL
FAQ

Frequently Asked Questions about LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor