
Mega Elements – Addons for Elementor Security & Risk Analysis
wordpress.org/plugins/mega-elements-addons-for-elementorA powerful and advanced all in one Elementor addons with unique styling features to create a beautiful website effortlessly.
Is Mega Elements – Addons for Elementor Safe to Use in 2026?
Generally Safe
Score 96/100Mega Elements – Addons for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "mega-elements-addons-for-elementor" v1.3.4 presents a mixed security posture. While the code analysis indicates good practices in several areas, such as 100% use of prepared statements for SQL queries and a high percentage of properly escaped output, there are significant concerns regarding its attack surface. The plugin exposes three AJAX handlers, all of which lack authentication checks, creating a direct pathway for attackers to interact with potentially sensitive functionalities without proper authorization. The absence of taint analysis results is noted, but this doesn't negate the identified direct vulnerabilities.
The plugin's vulnerability history is a major red flag. With six known medium-severity CVEs, despite none being currently unpatched, it indicates a pattern of introducing vulnerabilities, particularly Cross-Site Scripting (XSS) flaws. The fact that the last vulnerability was recorded in 2025-09-25, which is in the future, suggests a potential data anomaly or an outdated vulnerability database. However, the consistent history of medium-severity issues points to recurring coding weaknesses that need to be addressed to improve the plugin's overall security. The presence of file operations without explicit context in the static analysis also warrants careful scrutiny, although no specific vulnerabilities were directly flagged in that area by the provided data.
In conclusion, while the plugin demonstrates strengths in database interaction and output sanitization, the unprotected AJAX endpoints and the historical prevalence of XSS vulnerabilities represent critical weaknesses. The plugin's security can be significantly improved by implementing robust authentication and authorization checks on all entry points and diligently addressing the root causes of past XSS vulnerabilities. The future-dated vulnerability is a point of confusion and should be verified or corrected.
Key Concerns
- Unprotected AJAX handlers
- History of 6 medium severity CVEs
- Unescaped output rate (22% unescaped)
- File operation detected
Mega Elements – Addons for Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
Mega Elements – Addons for Elementor <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Timer Widget
Mega Elements <= 1.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
Mega Elements <= 1.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Mega Elements <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Mega Elements <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget
Mega Elements <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Mega Elements – Addons for Elementor Code Analysis
Output Escaping
Mega Elements – Addons for Elementor Attack Surface
AJAX Handlers 3
WordPress Hooks 25
Maintenance & Trust
Mega Elements – Addons for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
Mega Elements – Addons for Elementor Alternatives
Qi Addons For Elementor
qi-addons-for-elementor
Qi Addons for Elementor is a comprehensive library of 60+ custom, flexible & easily styled Elementor widgets developed by Qode Interactive.
ElementsReady Addons for Elementor
element-ready-lite
ElementsReady Addons for Elementor comes up with ultimate widgets like Post, Accordion, Portfolio, Testimonial, Nav menu, Carousel, Slider etc..
MT Addons for Elementor
mt-addons-for-elementor
MT Addons for Elementor with 50+ widgets, crafted by ModelTheme for dynamic, stylish website creation.
Easy Elements for Elementor – Addons & Website Templates
easy-elements
Modern Elementor Addons: A lightweight, powerful addon with beautifully designed widgets and extensions to build creative, animated websites.
Generic Elements
generic-elements-for-elementor
Generic Elements is the most complete elementor design toolkit which enhanced the power of elementor plugin.
Mega Elements – Addons for Elementor Developer Profile
5 plugins · 23K total installs
How We Detect Mega Elements – Addons for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mega-elements-addons-for-elementor/assets/admin/dashboard/css/sweetalert.css/wp-content/plugins/mega-elements-addons-for-elementor/assets/admin/dashboard/js/sweetalert.js/wp-content/plugins/mega-elements-addons-for-elementor/assets/admin/dashboard/css/dashboard.css/wp-content/plugins/mega-elements-addons-for-elementor/assets/admin/dashboard/js/dashboard.jsmega-elements-addons-for-elementor/assets/admin/dashboard/css/sweetalert.css?ver=mega-elements-addons-for-elementor/assets/admin/dashboard/js/sweetalert.js?ver=mega-elements-addons-for-elementor/assets/admin/dashboard/css/dashboard.css?ver=mega-elements-addons-for-elementor/assets/admin/dashboard/js/dashboard.js?ver=HTML / DOM Fingerprints
mega-elements-menu-item<!-- Mega Elements Dashbord Start --><!-- Mega Elements Dashbord End -->data-slug="mega-elements"data-nonce="ewfe_save_dashboard"data-action="ewfe_save_dashboard"MegaElementsAddons