MT Addons for Elementor Security & Risk Analysis

wordpress.org/plugins/mt-addons-for-elementor

MT Addons for Elementor with 50+ widgets, crafted by ModelTheme for dynamic, stylish website creation.

2K active installs v1.1.3 PHP 7.4+ WP 5.2+ Updated Aug 13, 2025
elementorelementor-addonselementor-elementselementor-widgetsmt-addons
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 7, 2025
Safety Verdict

Is MT Addons for Elementor Safe to Use in 2026?

Generally Safe

Score 99/100

MT Addons for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 7, 2025Updated 7mo ago
Risk Assessment

The "mt-addons-for-elementor" plugin version 1.1.3 exhibits a mixed security posture. While it demonstrates good practices in many areas, such as using prepared statements for all SQL queries and a very high percentage of properly escaped output, there are significant concerns regarding its attack surface. The plugin exposes one AJAX handler without any authentication checks, creating a direct entry point for potential attackers. Although the static analysis did not reveal any critical or high-severity taint flows, the presence of an unprotected AJAX handler means that any input processed by this handler could be susceptible to various attacks if not properly validated and sanitized within the handler itself.

The vulnerability history shows a single medium-severity Cross-Site Scripting (XSS) vulnerability in the past. While this vulnerability is noted as currently unpatched in the provided data, the fact that it's the only recorded vulnerability and is of medium severity suggests a generally decent security track record, but it also highlights the plugin's susceptibility to input validation flaws. The presence of a bundled library, Freemius v1.0, is also noted, and while its specific version isn't flagged as problematic in this data, outdated bundled libraries can sometimes be a vector for vulnerabilities.

In conclusion, the plugin has strengths in its secure handling of database queries and output escaping. However, the critical weakness lies in the unprotected AJAX endpoint, which represents a significant security risk that needs immediate attention. The historical XSS vulnerability, though medium, reinforces the need for robust input validation. Addressing the unprotected entry point is paramount to improving the plugin's overall security.

Key Concerns

  • Unprotected AJAX handler found
  • Bundled Freemius v1.0 library identified
  • One medium severity CVE on record
Vulnerabilities
1

MT Addons for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-22811medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

MT Addons for Elementor <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 7, 2025 Patched in 1.0.7 (8d)
Code Analysis
Analyzed Mar 16, 2026

MT Addons for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
61
1113 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

95% escaped1174 total outputs
Attack Surface
1 unprotected

MT Addons for Elementor Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_mt_addons_admin_ajaxadmin\dashboard\admin-ajax.php:24
WordPress Hooks 21
actionadmin_enqueue_scriptsadmin\dashboard\admin-ajax.php:26
actionadmin_initadmin\dashboard\admin-ajax.php:160
actionadmin_menuadmin\dashboard\admin-init.php:30
actionadmin_enqueue_scriptsadmin\dashboard\admin-init.php:33
actioncurrent_screenadmin\dashboard\admin-init.php:35
actionadmin_noticesadmin\dashboard\admin-init.php:43
actionadmin_noticesadmin\dashboard\admin-init.php:44
actionplugins_loadedincludes\class-mt-addons.php:142
actionadmin_enqueue_scriptsincludes\class-mt-addons.php:157
actionadmin_enqueue_scriptsincludes\class-mt-addons.php:158
actionwp_enqueue_scriptsincludes\class-mt-addons.php:173
actionwp_enqueue_scriptsincludes\class-mt-addons.php:174
actionelementor/editor/before_enqueue_stylesincludes\class-mt-addons.php:175
filterwp_kses_allowed_htmlmt-addons-for-elementor.php:230
actionelementor/widgets/registerpublic\shortcodes\elementor\functions-elementor.php:76
actioninitpublic\shortcodes\elementor\functions-elementor.php:139
actionelementor/elements/categories_registeredpublic\shortcodes\elementor\functions-elementor.php:155
actionelementor/frontend/after_enqueue_stylespublic\shortcodes\elementor\widgets\slider\includes\class-assets.php:14
actionelementor/frontend/after_register_scriptspublic\shortcodes\elementor\widgets\slider\includes\class-assets.php:15
actionelementor/initpublic\shortcodes\elementor\widgets\slider\includes\class-elementor.php:16
actionplugins_loadedpublic\shortcodes\elementor\widgets\slider\slider.php:19
Maintenance & Trust

MT Addons for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 13, 2025
PHP min version7.4
Downloads20K

Community Trust

Rating0/100
Number of ratings0
Active installs2K
Developer Profile

MT Addons for Elementor Developer Profile

Cristian Stan

2 plugins · 2K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect MT Addons for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mt-addons-for-elementor/assets/css/mt-addons-style.css/wp-content/plugins/mt-addons-for-elementor/assets/css/mt-addons-responsive.css/wp-content/plugins/mt-addons-for-elementor/assets/js/mt-addons.js/wp-content/plugins/mt-addons-for-elementor/public/js/mt-addons-public.js
Script Paths
/wp-content/plugins/mt-addons-for-elementor/assets/js/mt-addons.js/wp-content/plugins/mt-addons-for-elementor/public/js/mt-addons-public.js
Version Parameters
mt-addons-for-elementor/assets/css/mt-addons-style.css?ver=mt-addons-for-elementor/assets/css/mt-addons-responsive.css?ver=mt-addons-for-elementor/assets/js/mt-addons.js?ver=mt-addons-for-elementor/public/js/mt-addons-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
mt-addons-wrapmt-addons-settings
HTML Comments
<!-- MT ADDONS --><!-- END MT ADDONS --><!-- MT ADDONS ENDING --><!-- MT ADDONS MODULES -->+1 more
Data Attributes
data-mt-addons-id
JS Globals
mtAddonsmt_addons_params
REST Endpoints
/wp-json/mt-addons/v1/...
FAQ

Frequently Asked Questions about MT Addons for Elementor