Marquee Addons for Elementor – Essential Motion Widgets & Templates Security & Risk Analysis

wordpress.org/plugins/marquee-addons-for-elementor

Marquee Addons is a smooth video, text, image, and testimonial marquee carousel loop plugin for Elementor on WordPress

10K active installs v3.9.31 PHP 7.4+ WP 5.8+ Updated Mar 15, 2026
elementorelementor-addonsimage-marqueetext-marqueevideo-marquee
98
A · Safe
CVEs total2
Unpatched0
Last CVEDec 12, 2025
Safety Verdict

Is Marquee Addons for Elementor – Essential Motion Widgets & Templates Safe to Use in 2026?

Generally Safe

Score 98/100

Marquee Addons for Elementor – Essential Motion Widgets & Templates has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Dec 12, 2025Updated 20d ago
Risk Assessment

The "marquee-addons-for-elementor" plugin v3.9.31 demonstrates a generally good security posture based on the provided static analysis. The complete absence of unprotected AJAX handlers, REST API routes, shortcodes, and cron events, combined with robust SQL prepared statement usage and a high percentage of properly escaped output, indicates strong defensive coding practices. The presence of nonces, capability checks, and the lack of file operations further contribute to this positive assessment. However, the plugin's vulnerability history, with two known medium-severity Cross-Site Scripting (XSS) vulnerabilities, including one as recently as December 2025, is a significant concern that slightly tempers the otherwise positive static analysis findings. While there are currently no unpatched vulnerabilities, the recurring nature of XSS issues suggests a potential for oversight in input sanitization or output encoding that warrants continued vigilance.

Despite the strong static analysis results, the past XSS vulnerabilities are the primary area of concern. While current analysis shows good output escaping, the historical pattern of XSS suggests that input validation might not be consistently robust across all features or that subtle issues could have existed and been patched in previous versions. The single external HTTP request, while not explicitly flagged as dangerous, is a minor point to monitor for potential side-channel information leakage or dependency on potentially compromised external resources. Overall, the plugin is in a relatively good state, but the historical vulnerability data necessitates caution and thorough review of any future updates.

Key Concerns

  • Past medium severity XSS vulnerabilities
  • 2 total known CVEs
Vulnerabilities
2

Marquee Addons for Elementor – Essential Motion Widgets & Templates Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-8199medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

MarqueeAddons <= 2.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial Marquee Widget

Dec 12, 2025 Patched in 3.0.0 (1d)
CVE-2025-62923medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Marquee Addons for Elementor <= 3.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Oct 4, 2025 Patched in 3.8.3 (76d)
Code Analysis
Analyzed Mar 16, 2026

Marquee Addons for Elementor – Essential Motion Widgets & Templates Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
360 escaped
Nonce Checks
3
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

97% escaped373 total outputs
Attack Surface

Marquee Addons for Elementor – Essential Motion Widgets & Templates Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_deensimc_notice_dismissbase.php:56
authwp_ajax_deensimc_never_show_noticebase.php:57
WordPress Hooks 27
actionelementor/initbase.php:14
filterplugin_row_metabase.php:15
actionadmin_enqueue_scriptsbase.php:53
actionadmin_enqueue_scriptsbase.php:54
actionadmin_noticesbase.php:55
actionadmin_menuclasses\controls-manager.php:41
actionadmin_initclasses\controls-manager.php:42
actionadmin_enqueue_scriptsclasses\controls-manager.php:43
actionadmin_initclasses\controls-manager.php:44
actionelementor/widgets/registerclasses\widgets-manager.php:30
actionadmin_enqueue_scriptsincludes\feedback.php:13
actionadmin_headincludes\feedback.php:14
actionelementor/initincludes\widget.php:30
actionadmin_noticesincludes\widget.php:48
actionadmin_noticesincludes\widget.php:54
actionelementor/editor/before_enqueue_stylesincludes\widget.php:118
filterelementor/editor/localize_settingsincludes\widget.php:119
actionelementor/editor/after_enqueue_scriptsincludes\widget.php:120
actionelementor/frontend/after_enqueue_stylesincludes\widget.php:123
actionelementor/frontend/after_register_scriptsincludes\widget.php:124
actionelementor/frontend/widget/after_renderincludes\widget.php:125
actionelementor/elements/categories_registeredincludes\widget.php:126
actionelementor/editor/before_enqueue_stylesincludes\widget.php:127
actionelementor/editor/after_enqueue_scriptsincludes\widget.php:128
actionelementor/frontend/after_enqueue_scriptsincludes\widget.php:129
filterplugin_action_links_marquee-addons-for-elementor/marquee-addons-for-elementor.phpincludes\widget.php:130
actionplugins_loadedmarquee-addons-for-elementor.php:40
Maintenance & Trust

Marquee Addons for Elementor – Essential Motion Widgets & Templates Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 15, 2026
PHP min version7.4
Downloads264K

Community Trust

Rating100/100
Number of ratings6
Active installs10K
Developer Profile

Marquee Addons for Elementor – Essential Motion Widgets & Templates Developer Profile

Debuggers Studio

5 plugins · 11K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
147 days
View full developer profile
Detection Fingerprints

How We Detect Marquee Addons for Elementor – Essential Motion Widgets & Templates

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/marquee-addons-for-elementor/css/admin/admin.css/wp-content/plugins/marquee-addons-for-elementor/css/admin/feedback.css/wp-content/plugins/marquee-addons-for-elementor/js/admin/admin.js/wp-content/plugins/marquee-addons-for-elementor/js/admin/feedback.js/wp-content/plugins/marquee-addons-for-elementor/css/admin/notice.css
Version Parameters
marquee-addons-for-elementor/css/admin/admin.css?ver=marquee-addons-for-elementor/css/admin/feedback.css?ver=marquee-addons-for-elementor/js/admin/admin.js?ver=marquee-addons-for-elementor/js/admin/feedback.js?ver=marquee-addons-for-elementor/css/admin/notice.css?ver=

HTML / DOM Fingerprints

CSS Classes
deensimc-notice-wrapdeensimc-notice-icondeensimc-notice-contentdeensimc-btnsdeensimc-action-btnsdeensimc-dismiss-btndeensimc-dismiss-btns
Data Attributes
deensimc-feedback-notice
FAQ

Frequently Asked Questions about Marquee Addons for Elementor – Essential Motion Widgets & Templates