kitpack for persian elementor Security & Risk Analysis

wordpress.org/plugins/kitpack-for-persian-elementor

افزونه کیت پک، تمپلیت های فارسی و آماده را به المنتور اضافه می کند، همچنین مجموعه از فونت های فارسی و آیکن های ایرانی را نیز به افزونه سایت ساز المنتو …

300 active installs v2.1.1 PHP + WP 6.0+ Updated Nov 17, 2023
persians%d9%88%d8%b1%d8%af%d9%be%d8%b1%d8%b3%da%a9%db%8c%d8%aa-%d9%be%da%a9%d8%a7%d9%84%d9%85%d9%86%d8%aa%d9%88%d8%b1%d8%a7%d9%84%d9%85%d9%86%d8%aa%d9%88%d8%b1-%d9%81%d8%a7%d8%b1%d8%b3%db%8c
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is kitpack for persian elementor Safe to Use in 2026?

Generally Safe

Score 85/100

kitpack for persian elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The kitpack-for-persian-elementor plugin, version 2.1.1, exhibits a generally positive security posture with several good practices in place. The complete absence of SQL injection vulnerabilities due to the mandatory use of prepared statements for all queries is a significant strength. Furthermore, the plugin has no recorded vulnerabilities or CVEs, suggesting a history of stable and secure development. The majority of output escaping is properly handled, and there are no recorded dangerous functions or file operations, further contributing to its security.

However, there are areas of concern that temper the overall assessment. The presence of one AJAX handler without authentication checks presents a direct attack vector. While the total attack surface is relatively small, this single unprotected entry point requires attention. The rate of properly escaped output, while good at 70%, still indicates that a portion of the plugin's output might be susceptible to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved and not adequately sanitized before being displayed. The plugin also makes external HTTP requests, which, while not inherently a vulnerability, can become one if the data sent or received is not handled securely.

In conclusion, kitpack-for-persian-elementor 2.1.1 is largely secure, especially regarding data integrity through prepared statements and its clean vulnerability history. The primary risk lies with the single unprotected AJAX endpoint, which should be a priority for remediation. Addressing the remaining 30% of unescaped output would further enhance the plugin's security against potential XSS attacks.

Key Concerns

  • AJAX handler without auth checks
  • Unescaped output (30% of 659)
Vulnerabilities
None known

kitpack for persian elementor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

kitpack for persian elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
199
460 escaped
Nonce Checks
6
Capability Checks
2
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

70% escaped659 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
csf_export (admin\framework\functions\actions.php:62)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

kitpack for persian elementor Attack Surface

Entry Points6
Unprotected1

AJAX Handlers 6

authwp_ajax_csf-get-iconsadmin\framework\functions\actions.php:50
authwp_ajax_csf-exportadmin\framework\functions\actions.php:87
authwp_ajax_csf-importadmin\framework\functions\actions.php:123
authwp_ajax_csf-resetadmin\framework\functions\actions.php:150
authwp_ajax_csf-chosenadmin\framework\functions\actions.php:189
authwp_ajax_elementor_get_template_dataelementor\modules\kitpack-elementor-template-module.php:41
WordPress Hooks 33
actionwp_enqueue_scriptsadmin\framework\classes\abstract.class.php:20
actionadmin_menuadmin\framework\classes\admin-options.class.php:107
actionadmin_bar_menuadmin\framework\classes\admin-options.class.php:108
actionnetwork_admin_menuadmin\framework\classes\admin-options.class.php:112
filteradmin_footer_textadmin\framework\classes\admin-options.class.php:493
actionafter_setup_themeadmin\framework\classes\setup.class.php:73
actioninitadmin\framework\classes\setup.class.php:74
actionswitch_themeadmin\framework\classes\setup.class.php:75
actionadmin_enqueue_scriptsadmin\framework\classes\setup.class.php:76
actionwp_enqueue_scriptsadmin\framework\classes\setup.class.php:77
actionwp_headadmin\framework\classes\setup.class.php:78
filteradmin_body_classadmin\framework\classes\setup.class.php:79
actionadmin_footeradmin\framework\fields\icon\icon.php:41
actioncustomize_controls_print_footer_scriptsadmin\framework\fields\icon\icon.php:42
actionadmin_print_footer_scriptsadmin\framework\fields\link\link.php:65
actionprint_default_editor_scriptsadmin\framework\fields\wp_editor\wp_editor.php:62
actionadmin_menuadmin\framework\views\welcome.php:19
filterplugin_action_linksadmin\framework\views\welcome.php:20
filterplugin_row_metaadmin\framework\views\welcome.php:21
actionelementor/initelementor\modules\kitpack-elementor-template-module.php:30
actionelementor/ajax/register_actionselementor\modules\kitpack-elementor-template-module.php:39
actionplugins_loadedincludes\class-kitpack-lite.php:156
actionadmin_enqueue_scriptsincludes\class-kitpack-lite.php:171
actionadmin_enqueue_scriptsincludes\class-kitpack-lite.php:172
actionwp_enqueue_scriptsincludes\class-kitpack-lite.php:191
actionwp_enqueue_scriptsincludes\class-kitpack-lite.php:192
actionelementor/editor/before_enqueue_scriptsincludes\class-kitpack-lite.php:209
filterelementor/icons_manager/additional_tabsincludes\class-kitpack-lite.php:213
actionelementor/editor/before_enqueue_scriptsincludes\class-kitpack-lite.php:217
actionelementor/preview/enqueue_stylesincludes\class-kitpack-lite.php:218
filterelementor/fonts/groupsincludes\class-kitpack-lite.php:222
filterelementor/fonts/additional_fontsincludes\class-kitpack-lite.php:223
actionelementor/frontend/before_enqueue_stylesincludes\class-kitpack-lite.php:224
Maintenance & Trust

kitpack for persian elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.9
Last updatedNov 17, 2023
PHP min version
Downloads15K

Community Trust

Rating100/100
Number of ratings1
Active installs300
Developer Profile

kitpack for persian elementor Developer Profile

kitpack

1 plugin · 300 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect kitpack for persian elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kitpack-for-persian-elementor/admin/css/kitpack-lite-admin.css
Version Parameters
kitpack-lite-admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
kitpack-lite-admin
FAQ

Frequently Asked Questions about kitpack for persian elementor