
ingenidev Code Widget for Elementor Security & Risk Analysis
wordpress.org/plugins/ingenidev-code-widget-for-elementorThis Elementor plugin allows you to display and format a code container that includes for the viewer an easy to use copy to clipboard functionality.
Is ingenidev Code Widget for Elementor Safe to Use in 2026?
Generally Safe
Score 100/100ingenidev Code Widget for Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "ingenidev-code-widget-for-elementor" v1.0.4 exhibits a generally good security posture due to its avoidance of dangerous functions, proper SQL statement preparation, and output escaping. The absence of known CVEs and vulnerability history is also a positive indicator. However, a significant concern arises from the presence of one unprotected AJAX handler within its attack surface. This unprotected entry point could potentially be exploited if it processes user-supplied data without proper validation or authorization, creating an avenue for attacks.
The static analysis shows no critical or high severity taint flows, reinforcing that while there's an unprotected AJAX handler, it doesn't appear to be directly processing unsanitized user input in a way that leads to immediate critical vulnerabilities according to this specific analysis. The plugin also lacks nonce checks on its AJAX actions, which is a common security mechanism to prevent Cross-Site Request Forgery (CSRF) attacks. While the vulnerability history is clean, the lack of authorization on the AJAX handler is a weakness that needs to be addressed to enhance the plugin's overall security.
In conclusion, the plugin demonstrates good development practices in several areas. The clean vulnerability history and proper handling of SQL and output escaping are strengths. Nevertheless, the unprotected AJAX handler represents a notable security risk that could be exploited. The absence of nonce checks further weakens its defense against certain attack vectors. Addressing these identified weaknesses is crucial for a robust security profile.
Key Concerns
- Unprotected AJAX handler
- Missing nonce checks on AJAX
ingenidev Code Widget for Elementor Security Vulnerabilities
ingenidev Code Widget for Elementor Code Analysis
Output Escaping
ingenidev Code Widget for Elementor Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
ingenidev Code Widget for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
ingenidev Code Widget for Elementor Alternatives
Nexter Extension – Security, Performance, Code Snippets & Site Toolkit
nexter-extension
Replace 50+ WordPress Plugins: Free Theme Builder, Code Snippets, Image Optimizer (WebP/AVIF), SMTP Email, Security Hardening, Performance & More
Copy to Clipboard for WordPress
copy-to-clipboard-for-wp
Copy to Clipboard for WordPress is a powerful and user-friendly plugin designed to enhance the copy-and-paste functionality on your WordPress website.
Cipher
cipher
Cipher allows commenters to publish (pre-formatted) code.
Snippet Highlight
snippet-highlight
Highlights your code snippets. With line numbering.
Clipboard Snippet Copier
clipboard-snippet-copier
Copy shortcodes or code snippets to clipboard with a single click using AJAX – without displaying the actual code.
ingenidev Code Widget for Elementor Developer Profile
11 plugins · 1K total installs
How We Detect ingenidev Code Widget for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ingenidev-code-widget-for-elementor/css/code-widget.css/wp-content/plugins/ingenidev-code-widget-for-elementor/js/ingenidev_ccwe_copy_code.js/wp-content/plugins/ingenidev-code-widget-for-elementor/js/ingenidev_ccwe_dismiss_notice.jsHTML / DOM Fingerprints
ingenidev-welcome-noticeingenidev-ccwe-ajax-objingenidev_ccwe_ajax_obj