Live Copy Paste – Ultimate Elementor Cross-Domain Design Transfer Security & Risk Analysis

wordpress.org/plugins/live-copy

🎯 Instantly copy and paste Elementor designs across domains. Boost workflow, duplicate pages, and transfer layouts with perfect fidelity.

0 active installs v1.0.13 PHP 7.4+ WP 5.0+ Updated Sep 5, 2025
cross-domain-designdesign-transferelementor-copy-pasteelementor-workflowpage-duplicator
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Live Copy Paste – Ultimate Elementor Cross-Domain Design Transfer Safe to Use in 2026?

Generally Safe

Score 100/100

Live Copy Paste – Ultimate Elementor Cross-Domain Design Transfer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The 'live-copy' plugin v1.0.13 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for all SQL queries and ensuring all output is properly escaped. It also has no recorded vulnerabilities (CVEs) or past security incidents, suggesting a potentially stable codebase. However, a significant concern arises from its attack surface. The plugin exposes two AJAX handlers, both of which lack any authentication or capability checks. This means that any user, regardless of their role or permissions, can trigger these AJAX actions, creating a substantial risk for unauthorized operations if these handlers are not inherently designed to be safe for anonymous access.

The lack of taint analysis flows and dangerous function calls is reassuring, indicating no immediately obvious critical code execution or data manipulation vulnerabilities. The absence of shortcodes, cron events, REST API routes, file operations, and external HTTP requests further limits the potential attack vectors. Despite the strengths in SQL handling and output escaping, the unprotected AJAX endpoints represent a clear and present danger. The absence of any recorded vulnerabilities, while positive, could also be interpreted as a lack of extensive security auditing or simply good fortune up to this point. The plugin's primary weakness lies in its insufficient access control for its AJAX entry points.

Key Concerns

  • 2 AJAX handlers without auth checks
  • 0 Nonce checks
  • 0 Capability checks
Vulnerabilities
None known

Live Copy Paste – Ultimate Elementor Cross-Domain Design Transfer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Live Copy Paste – Ultimate Elementor Cross-Domain Design Transfer Release Timeline

v1.0.13Current
v1.0.12
v1.0.7
v1.0.1
Code Analysis
Analyzed Mar 17, 2026

Live Copy Paste – Ultimate Elementor Cross-Domain Design Transfer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Attack Surface
2 unprotected

Live Copy Paste – Ultimate Elementor Cross-Domain Design Transfer Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

noprivwp_ajax_ellc_copy_dataincludes\class-live-copy.php:26
authwp_ajax_ellc_copy_dataincludes\class-live-copy.php:27
WordPress Hooks 4
actionwp_enqueue_scriptsincludes\class-live-copy.php:40
actionwp_enqueue_scriptsincludes\class-live-copy.php:41
actionplugin_loadedlive-copy.php:19
actionwplive-copy.php:35
Maintenance & Trust

Live Copy Paste – Ultimate Elementor Cross-Domain Design Transfer Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 5, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Live Copy Paste – Ultimate Elementor Cross-Domain Design Transfer Developer Profile

wowDevs

7 plugins · 2K total installs

98
trust score
Avg Security Score
97/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect Live Copy Paste – Ultimate Elementor Cross-Domain Design Transfer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/live-copy/assets/css/style.css/wp-content/plugins/live-copy/assets/js/script.js
Script Paths
/wp-content/plugins/live-copy/assets/js/script.js
Version Parameters
live-copy/style.css?ver=live-copy/script.js?ver=

HTML / DOM Fingerprints

JS Globals
ElLiveCopyData
REST Endpoints
/wp-json/live-copy
FAQ

Frequently Asked Questions about Live Copy Paste – Ultimate Elementor Cross-Domain Design Transfer