Medical Addon for Elementor Security & Risk Analysis

wordpress.org/plugins/medical-addon-for-elementor

Medical Addon for Elementor is an Elementor Addons for Medical Websites.

1K active installs v1.6.4 PHP 7.4+ WP 6.3+ Updated Aug 12, 2025
addonselementorelementor-extensionselementor-widgetmedical
75
B · Generally Safe
CVEs total3
Unpatched1
Last CVEAug 1, 2025
Safety Verdict

Is Medical Addon for Elementor Safe to Use in 2026?

Mostly Safe

Score 75/100

Medical Addon for Elementor is generally safe to use. 3 past CVEs were resolved. Keep it updated.

3 known CVEs 1 unpatched Last CVE: Aug 1, 2025Updated 7mo ago
Risk Assessment

The static analysis of "medical-addon-for-elementor" v1.6.4 reveals a seemingly strong internal security posture, with no identified dangerous functions, file operations, external requests, or SQL queries using prepared statements. The plugin also demonstrates a high percentage of properly escaped output. However, the complete absence of entry points (AJAX handlers, REST API routes, shortcodes, cron events) that lack authorization checks, coupled with zero detected taint flows, suggests a potentially limited feature set or that the analysis might have missed certain plugin functionalities.

The vulnerability history presents a significant concern. With three known CVEs, one of which remains unpatched, this indicates a recurring pattern of security weaknesses. The common vulnerability types, including Authorization Bypass and Cross-site Scripting, are critical for any web application. The recent date of the last vulnerability (2025-08-01) is particularly alarming, suggesting that even with updates, new vulnerabilities are being introduced or not fully mitigated.

In conclusion, while the plugin exhibits good practices in its code structure regarding output escaping and prepared statements, the history of multiple, recent, and unpatched vulnerabilities significantly outweighs these strengths. The lack of identifiable entry points in the static analysis is unusual and warrants further investigation to ensure comprehensive security coverage. The presence of unpatched medium-severity vulnerabilities translates to a moderate to high risk for users.

Key Concerns

  • Unpatched CVE detected
  • Multiple medium severity CVEs
  • Vulnerabilities common: Auth Bypass & XSS
  • Recent vulnerability discovered
  • No capability checks detected
  • No nonce checks detected
Vulnerabilities
3

Medical Addon for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2024 · unpatched
2024
2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2025-8212medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Medical Addon for Elementor <= 1.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typewriter Widget

Aug 1, 2025 Patched in 1.6.5 (21d)
CVE-2024-12046medium · 4.3Authorization Bypass Through User-Controlled Key

Medical Addon for Elementor <= 1.6.2 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via Shortcode

Feb 3, 2025 Patched in 1.6.3 (1d)
CVE-2024-44024medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Medical Addon for Elementor <= 1.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 24, 2024Unpatched
Code Analysis
Analyzed Mar 16, 2026

Medical Addon for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
49
475 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped524 total outputs
Attack Surface

Medical Addon for Elementor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
actionplugins_loadedelementor\em-setup.php:33
actionelementor/editor/before_enqueue_scriptselementor\em-setup.php:35
actionelementor/frontend/after_enqueue_scriptselementor\em-setup.php:41
actionadmin_noticeselementor\em-setup.php:66
actionadmin_noticeselementor\em-setup.php:72
actionelementor/elements/categories_registeredelementor\em-setup.php:80
actionelementor/elements/categories_registeredelementor\em-setup.php:81
actionelementor/elements/categories_registeredelementor\em-setup.php:82
actionelementor/widgets/widgets_registeredelementor\em-setup.php:85
actionelementor/widgets/widgets_registeredelementor\em-setup.php:86
actionelementor/widgets/widgets_registeredelementor\em-setup.php:87
actionafter_switch_themeelementor\em-setup.php:233
actionpt-ocdi/after_content_import_executionelementor\em-setup.php:241
filterexcerpt_lengthelementor\em-setup.php:257
filterexcerpt_moreelementor\em-setup.php:282
actioninitmedical-addon-for-elementor.php:50
actionadmin_noticesmedical-addon-for-elementor.php:57
actionplugins_loadedmedical-addon-for-elementor.php:61
actionwp_enqueue_scriptsmedical-addon-for-elementor.php:109
Maintenance & Trust

Medical Addon for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedAug 12, 2025
PHP min version7.4
Downloads25K

Community Trust

Rating100/100
Number of ratings1
Active installs1K
Developer Profile

Medical Addon for Elementor Developer Profile

nicheaddons

7 plugins · 19K total installs

75
trust score
Avg Security Score
82/100
Avg Patch Time
74 days
View full developer profile
Detection Fingerprints

How We Detect Medical Addon for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/medical-addon-for-elementor/assets/css/niche-frame.css/wp-content/plugins/medical-addon-for-elementor/assets/css/font-awesome.min.css/wp-content/plugins/medical-addon-for-elementor/assets/css/animate.min.css/wp-content/plugins/medical-addon-for-elementor/assets/css/themify-icons.min.css/wp-content/plugins/medical-addon-for-elementor/assets/css/linea.min.css/wp-content/plugins/medical-addon-for-elementor/assets/css/magnific-popup.min.css/wp-content/plugins/medical-addon-for-elementor/assets/css/owl.carousel.min.css/wp-content/plugins/medical-addon-for-elementor/assets/css/slick-theme.min.css+20 more

HTML / DOM Fingerprints

CSS Classes
namedical-addon-widget-titlenamedical-slider-itemnamedical-testimonial-item
JS Globals
NAMEP_PLUGIN_URLNAMEP_PLUGIN_PATHNAMEP_PLUGIN_ASTSNAMEP_PLUGIN_IMGSNAMEP_PLUGIN_CSSNAMEP_PLUGIN_SCRIPTS+4 more
FAQ

Frequently Asked Questions about Medical Addon for Elementor