Nemesis All-in-One | Newspaper Builder Elementor Extention Security & Risk Analysis

wordpress.org/plugins/nemesis-all-in-one

The Nemesis All-in-One addon for Elementor is the only one plugin for building blog post pages.

10 active installs v1.1.3 PHP 7.4+ WP 6.0+ Updated Unknown
elementorelementor-widgetsmagazinenewsnewspaper
79
B · Generally Safe
CVEs total1
Unpatched1
Last CVEApr 1, 2025
Safety Verdict

Is Nemesis All-in-One | Newspaper Builder Elementor Extention Safe to Use in 2026?

Mostly Safe

Score 79/100

Nemesis All-in-One | Newspaper Builder Elementor Extention is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Apr 1, 2025
Risk Assessment

The static analysis of Nemesis All-In-One v1.1.3 presents a generally positive security posture, with no apparent attack surface identified and a commendable 85% of output being properly escaped. The code also demonstrates good practices by utilizing prepared statements for all SQL queries and avoiding potentially risky operations like file operations or external HTTP requests. There are no detected dangerous functions or taint flows, suggesting a robust internal code structure regarding immediate threats within this version.

However, a significant concern arises from the plugin's vulnerability history. The presence of one known medium severity Cross-Site Scripting (XSS) vulnerability, which is currently unpatched, indicates a potential risk to user data and site integrity. While the static analysis for this specific version is clean, the historical vulnerability suggests that the plugin may have had exploitable flaws in the past, and it's crucial to ensure this specific CVE is addressed to maintain a secure environment.

In conclusion, Nemesis All-In-One v1.1.3 exhibits strong internal security practices by minimizing its attack surface and handling data responsibly within its codebase. The primary weakness lies in the unresolved medium-severity XSS vulnerability, which overshadows the otherwise positive findings. Prioritizing the patching of this known vulnerability is essential for a truly secure implementation.

Key Concerns

  • Unpatched medium severity CVE
Vulnerabilities
1

Nemesis All-in-One | Newspaper Builder Elementor Extention Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-31849medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Nemesis All-in-One <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 1, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Nemesis All-in-One | Newspaper Builder Elementor Extention Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
51 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

85% escaped60 total outputs
Attack Surface

Nemesis All-in-One | Newspaper Builder Elementor Extention Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_enqueue_scriptsadmin\admin-page.php:11
actionadmin_menuadmin\admin-page.php:12
actioninitnemesis-all-in-one.php:39
actionplugins_loadednemesis-all-in-one.php:42
actionadmin_noticesnemesis-all-in-one.php:71
actionadmin_noticesnemesis-all-in-one.php:77
actionadmin_noticesnemesis-all-in-one.php:83
actionelementor/elements/categories_registerednemesis-all-in-one.php:88
actionelementor/frontend/after_enqueue_stylesnemesis-all-in-one.php:91
actionelementor/widgets/registernemesis-all-in-one.php:94
Maintenance & Trust

Nemesis All-in-One | Newspaper Builder Elementor Extention Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Nemesis All-in-One | Newspaper Builder Elementor Extention Developer Profile

fbtemplates

1 plugin · 10 total installs

79
trust score
Avg Security Score
79/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Nemesis All-in-One | Newspaper Builder Elementor Extention

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nemesis-all-in-one/assets/bootstrap/bootstrap-grid.min.css/wp-content/plugins/nemesis-all-in-one/assets/css/style.css/wp-content/plugins/nemesis-all-in-one/assets/css/admin-styles.css/wp-content/plugins/nemesis-all-in-one/assets/js/admin-scripts.js
Version Parameters
nemesis-all-in-one/assets/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
nemesis-pro-link
JS Globals
Nemesis_Newspaper_Builder
FAQ

Frequently Asked Questions about Nemesis All-in-One | Newspaper Builder Elementor Extention