AMP Designs for Elementor by LevelUP Security & Risk Analysis

wordpress.org/plugins/levelup

LevelUP is a Design Library for Elementor that offers unlimited pre-built designs for FREE. We will be creating and releasing new design elements ever …

10 active installs v1.1 PHP + WP 3.6+ Updated May 26, 2021
ampelementorpage-builderperformanceseo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AMP Designs for Elementor by LevelUP Safe to Use in 2026?

Generally Safe

Score 85/100

AMP Designs for Elementor by LevelUP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The 'levelup' v1.1 plugin presents a mixed security posture. On the positive side, it demonstrates good practices in its SQL query handling, exclusively using prepared statements, and avoids critical vulnerabilities indicated by taint analysis. The absence of any recorded CVEs, historical or current, suggests a generally stable codebase. However, there are significant concerns regarding its attack surface, particularly the presence of three unprotected AJAX handlers. While the plugin implements nonce and capability checks, the unprotected entry points represent a direct avenue for potential unauthorized actions if exploited. The moderate rate of properly escaped output (45%) also introduces a risk of cross-site scripting (XSS) vulnerabilities, although the severity of these is not explicitly detailed in the provided data.

Overall, the plugin has strengths in its data handling and lack of critical security flaws. The primary weaknesses lie in the exposure of AJAX functionality without proper authentication or authorization, and the potential for XSS due to insufficient output escaping. While the vulnerability history is clean, the static analysis reveals actionable risks that require attention to prevent future security incidents. A balanced approach to improving security would involve addressing the unprotected AJAX handlers and increasing the rate of output escaping.

Key Concerns

  • Unprotected AJAX handlers found
  • Moderate percentage of unescaped output
Vulnerabilities
None known

AMP Designs for Elementor by LevelUP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

AMP Designs for Elementor by LevelUP Release Timeline

v1.1Current
v1.0.1
Code Analysis
Analyzed Mar 16, 2026

AMP Designs for Elementor by LevelUP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
5 prepared
Unescaped Output
61
49 escaped
Nonce Checks
3
Capability Checks
6
File Operations
7
External Requests
4
Bundled Libraries
0

SQL Query Safety

100% prepared5 total queries

Output Escaping

45% escaped110 total outputs
Attack Surface
3 unprotected

AMP Designs for Elementor by LevelUP Attack Surface

Entry Points7
Unprotected3

AJAX Handlers 7

authwp_ajax_levelup_get_designinc\common-functions.php:363
authwp_ajax_levelup_send_query_messageinc\composite-menu.php:7
authwp_ajax_levelup_enable_modules_upgreadinc\composite-menu.php:8
authwp_ajax_levelup_connect_design_library_activateinc\composite-menu.php:9
authwp_ajax_levelup_update_design_libraryinc\designlib\sync_page.php:33
authwp_ajax_levelup_update_design_versioninc\designlib\sync_page.php:240
authwp_ajax_levelup_remove_keyinc\designlib\sync_page.php:320
WordPress Hooks 32
actionadmin_menuadmin\admin-settings.php:17
actionadmin_noticesadmin\admin-settings.php:18
actionadmin_initadmin\admin-settings.php:22
actionadmin_noticesadmin\admin-settings.php:23
actionampforwp_before_headinc\common-functions.php:96
actionamp_post_template_cssinc\common-functions.php:172
actionamp_post_template_cssinc\common-functions.php:183
filterelementor/frontend/the_contentinc\common-functions.php:343
filterexcerpt_moreinc\common-functions.php:357
filteramp_post_template_fileinc\common-functions.php:410
filteramp_post_template_datainc\common-functions.php:474
actionadmin_menuinc\composite-menu.php:6
actioninitinc\designlib\register-post.php:5
actioninitinc\designlib\register-post.php:6
actionadmin_enqueue_scriptsinc\designlib\sync_page.php:14
actionadmin_initinc\designlib\sync_page.php:220
actionlevelup_daily_eventinc\designlib\sync_page.php:249
filterimage_resize_dimensionsinc\image-aqua.php:51
actionelementor/elements/categories_registeredlevelup-widgets.php:37
actionelementor/widgets/widgets_registeredlevelup-widgets.php:38
actionprint_media_templateslevelup-widgets.php:41
actionlevelup_modal_stylelevelup-widgets.php:42
actionelementor/editor/before_enqueue_scriptslevelup-widgets.php:43
actionelementor/frontend/after_register_scriptslevelup-widgets.php:45
actionelementor/frontend/after_enqueue_styleslevelup-widgets.php:46
actionelementor/editor/before_enqueue_styleslevelup-widgets.php:47
actionadmin_noticeslevelup.php:47
actionadmin_noticeslevelup.php:53
actionplugins_loadedlevelup.php:62
actionactivated_pluginlevelup.php:95
actionpre_get_postslevelup.php:113
actionelementor/initlevelup.php:115

Scheduled Events 1

levelup_daily_event
Maintenance & Trust

AMP Designs for Elementor by LevelUP Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedMay 26, 2021
PHP min version
Downloads2K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Developer Profile

AMP Designs for Elementor by LevelUP Developer Profile

Mohammed Kaludi

3 plugins · 91K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
416 days
View full developer profile
Detection Fingerprints

How We Detect AMP Designs for Elementor by LevelUP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/levelup/admin/css/custom-style.css/wp-content/plugins/levelup/admin/css/admin-style.css/wp-content/plugins/levelup/admin/js/script.js/wp-content/plugins/levelup/inc/vendor/customizer-extra/css/header-builder.css/wp-content/plugins/levelup/inc/vendor/customizer-extra/js/header-builder.js/wp-content/plugins/levelup/inc/designlib/css/designlib.css/wp-content/plugins/levelup/inc/designlib/js/designlib.js/wp-content/plugins/levelup/assets/css/frontend.css+1 more
Script Paths
/wp-content/plugins/levelup/admin/js/script.js/wp-content/plugins/levelup/inc/vendor/customizer-extra/js/header-builder.js/wp-content/plugins/levelup/inc/designlib/js/designlib.js/wp-content/plugins/levelup/assets/js/frontend.js
Version Parameters
levelup/admin/css/custom-style.css?ver=levelup/admin/css/admin-style.css?ver=levelup/admin/js/script.js?ver=levelup/inc/vendor/customizer-extra/css/header-builder.css?ver=levelup/inc/vendor/customizer-extra/js/header-builder.js?ver=levelup/inc/designlib/css/designlib.css?ver=levelup/inc/designlib/js/designlib.js?ver=levelup/assets/css/frontend.css?ver=levelup/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
levelup_design_librarylevelup-design-itemlevelup-design-previewlevelup-design-titlelevelup_add_design
HTML Comments
<!-- Elementor T
Data Attributes
data-noncedata-templatedata-design-iddata-design-namedata-preview-urldata-category-slug+5 more
JS Globals
levelup_data
FAQ

Frequently Asked Questions about AMP Designs for Elementor by LevelUP