LC Addons Kit for Elementor Security & Risk Analysis

wordpress.org/plugins/lc-addons-kit-for-elementor

A powerful Elementor addon plugin that offers 41+ widgets categorized into 'LC Kit' and 'LC Header & Footer kit' with a dashboard control panel.

0 active installs v1.1.0 PHP 7.4+ WP 5.0+ Updated Apr 6, 2026
addonselementorlc-kitpage-builderwidgets
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LC Addons Kit for Elementor Safe to Use in 2026?

Generally Safe

Score 100/100

LC Addons Kit for Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'lc-addons-kit-for-elementor' plugin v1.0.1 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the high percentage of properly escaped output (95%) significantly mitigates the risk of cross-site scripting (XSS) vulnerabilities. The plugin also appears to have a limited attack surface, with only one REST API route identified, and importantly, this route has a permission callback, indicating proper access control. The lack of known CVEs and a clean vulnerability history suggests a history of secure development or at least no publicly disclosed critical issues.

Despite these strengths, there are a few areas that, while not indicating immediate critical flaws, warrant attention for further hardening. The complete absence of nonce checks across all entry points, especially in conjunction with the single REST API endpoint, could be a point of concern if that endpoint were to become more complex or handle sensitive actions in future versions. While no taint flows were found, this could be due to the limited complexity of the analyzed code; a more extensive analysis might reveal subtle issues. The single capability check is present, which is positive, but the overall lack of checks on other potential entry points (even though none were found) suggests a reliance on the limited attack surface rather than explicit, layered security measures.

In conclusion, 'lc-addons-kit-for-elementor' v1.0.1 is generally well-secured, with excellent practices in place for output escaping and SQL query handling, and no known historical vulnerabilities. The primary area for improvement would be the introduction of nonce checks for all interactive endpoints as a defense-in-depth strategy, even with the current limited attack surface and permission callbacks. The plugin benefits from a small attack surface and robust output handling, making it a relatively safe choice at this version.

Key Concerns

  • No nonce checks on entry points
Vulnerabilities
None known

LC Addons Kit for Elementor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

LC Addons Kit for Elementor Release Timeline

v1.1.0Current
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

LC Addons Kit for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
396 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped416 total outputs
Attack Surface

LC Addons Kit for Elementor Attack Surface

Entry Points1
Unprotected0

REST API Routes 1

POST/wp-json/lcake-kit/v1/save-settingsadmin\lcake-admin-page.php:76
WordPress Hooks 12
actionadmin_menuadmin\lcake-admin-page.php:15
actionadmin_initadmin\lcake-admin-page.php:16
actionadmin_enqueue_scriptsadmin\lcake-admin-page.php:17
actionadmin_initadmin\lcake-admin-page.php:18
actionrest_api_initadmin\lcake-admin-page.php:19
filterelementor/icons_manager/additional_tabsincludes\lcake-lib.php:8
actionelementor/widgets/registerincludes\lcake-widget-loader.php:10
actionelementor/elements/categories_registeredincludes\lcake-widget-loader.php:11
actionelementor/frontend/after_register_scriptsincludes\lcake-widget-loader.php:12
actionelementor/frontend/after_register_stylesincludes\lcake-widget-loader.php:13
actionplugins_loadedlc-addons-kit-for-elementor.php:28
actionadmin_noticeslc-addons-kit-for-elementor.php:41
Maintenance & Trust

LC Addons Kit for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 6, 2026
PHP min version7.4
Downloads250

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

LC Addons Kit for Elementor Developer Profile

Loinecoders

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LC Addons Kit for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lc-addons-kit-for-elementor/admin/build/index.js/wp-content/plugins/lc-addons-kit-for-elementor/admin/css/admin-styles.css
Script Paths
/wp-content/plugins/lc-addons-kit-for-elementor/admin/build/index.js
Version Parameters
lc-addons-kit-for-elementor/admin/css/admin-styles.css?ver=

HTML / DOM Fingerprints

CSS Classes
lcake-kit-react-root
Data Attributes
lcake-kit-react-root
JS Globals
LCAKE_SETTINGS
REST Endpoints
/wp-json/lcake-kit/v1/save-settings
FAQ

Frequently Asked Questions about LC Addons Kit for Elementor