المنتور فارسی Security & Risk Analysis

wordpress.org/plugins/persian-elementor

بسته کامل فارسی‌ساز المنتور با 13 فونت ایرانی، ترجمه المنتور و المنتور پرو، آیکون‌های ایرانی، تقویم شمسی، ویجت‌های نقشه نشان و آپارات.

50K active installs v2.7.16 PHP 7.4+ WP 5.0+ Updated Jan 28, 2026
elementorpersian%d8%a7%d9%84%d9%85%d9%86%d8%aa%d9%88%d8%b1
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is المنتور فارسی Safe to Use in 2026?

Generally Safe

Score 100/100

المنتور فارسی has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The plugin "persian-elementor" v2.7.16 exhibits a generally good security posture based on the provided static analysis. It correctly implements prepared statements for all SQL queries, significantly mitigating SQL injection risks. The high percentage of properly escaped output (90%) is also a positive indicator, reducing the likelihood of cross-site scripting (XSS) vulnerabilities. The absence of known CVEs and a clean vulnerability history suggest a history of secure development or effective patching by developers.

However, the analysis does reveal areas for improvement. While the total number of entry points is low and none are reported as unprotected, the presence of "flows with unsanitized paths" in the taint analysis (3 flows) is a concern. Although no critical or high severity issues were identified in taint analysis, unsanitized paths can potentially lead to vulnerabilities if not handled carefully. Furthermore, the plugin performs 4 external HTTP requests, which, while not inherently insecure, can become a vector for issues if the target endpoints are compromised or the data being sent is not adequately sanitized before transmission.

In conclusion, "persian-elementor" v2.7.16 appears to be a relatively secure plugin with good foundational security practices like prepared SQL statements and output escaping. The lack of historical vulnerabilities is reassuring. The primary area of concern lies in the identified unsanitized paths within the taint analysis, which warrants further investigation by the developers to ensure no exploitable conditions exist. The external HTTP requests, while not a direct vulnerability, represent a potential attack surface that should be monitored.

Key Concerns

  • 3 flows with unsanitized paths
  • 4 external HTTP requests
Vulnerabilities
None known

المنتور فارسی Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

المنتور فارسی Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
133 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

90% escaped147 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

5 flows3 with unsanitized paths
process_payment_request (widget\zarinpal\zarinpal-ajax.php:28)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

المنتور فارسی Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_zarinpal_payment_requestwidget\zarinpal\zarinpal-ajax.php:18
noprivwp_ajax_zarinpal_payment_requestwidget\zarinpal\zarinpal-ajax.php:19
WordPress Hooks 44
filterelementor/fonts/groupsincludes\fonts.php:33
filterelementor/fonts/additional_fontsincludes\fonts.php:38
actionelementor_pro/forms/fields/registerincludes\form-fields.php:26
filterelementor/icons_manager/nativeincludes\icon.php:8
actionadmin_initincludes\options.php:7
actionadmin_menuincludes\options.php:16
actioninitincludes\translate.php:35
actionadmin_initincludes\translate.php:37
actionplugins_loadedpersian-elementor.php:34
actionelementor/frontend/after_enqueue_stylesplugin.php:76
actionelementor/editor/before_enqueue_scriptsplugin.php:81
actionelementor/frontend/before_enqueue_stylesplugin.php:82
actionelementor/admin/dashboard_overview_widget/after_versionplugin.php:89
actionelementor/editor/before_enqueue_scriptsplugin.php:95
actionelementor/preview/enqueue_stylesplugin.php:96
actionelementor/app/initplugin.php:97
actionadmin_enqueue_scriptsplugin.php:98
actionelementor/editor/after_enqueue_scriptsplugin.php:161
actionelementor/initwidget\aparat-video.php:28
actionelementor/element/video/section_video/before_section_endwidget\aparat-video.php:33
actionelementor/element/video/section_video/after_section_endwidget\aparat-video.php:36
filterelementor/frontend/widget/before_renderwidget\aparat-video.php:39
filterelementor/widget/render_contentwidget\aparat-video.php:42
actionelementor/editor/after_enqueue_scriptswidget\aparat-video.php:45
actionelementor/controls/registerwidget\class-group-control-typography.php:97
actionelementor/controls/controls_registeredwidget\class-group-control-typography.php:105
actionelementor/preview/initwidget\form-fields\persian-date.php:18
actionwp_enqueue_scriptswidget\form-fields\persian-date.php:19
actionelementor/editor/after_enqueue_scriptswidget\form-fields\persian-date.php:20
actionelementor/preview/enqueue_styleswidget\form-fields\persian-date.php:21
actionelementor/frontend/after_enqueue_scriptswidget\form-fields\persian-date.php:22
actionwp_footerwidget\form-fields\persian-date.php:66
actionwp_enqueue_scriptswidget\neshan-map.php:18
actionelementor/editor/before_enqueue_scriptswidget\neshan-map.php:19
actionelementor/preview/enqueue_scriptswidget\neshan-map.php:20
actionelementor/editor/after_enqueue_scriptswidget\neshan-map.php:23
actionelementor/editor/after_enqueue_styleswidget\neshan-map.php:24
actionelementor/preview/enqueue_scriptswidget\neshan-map.php:27
actionelementor/preview/enqueue_styleswidget\neshan-map.php:28
actionelementor/widgets/registerwidget\neshan-map.php:66
actionelementor/editor/after_enqueue_styleswidget\neshan-map.php:86
actiontemplate_redirectwidget\zarinpal\zarinpal-ajax.php:22
actionwp_footerwidget\zarinpal\zarinpal-ajax.php:184
actionelementor/widgets/widgets_registeredwidget\zarinpal\zarinpal-register.php:17
Maintenance & Trust

المنتور فارسی Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 28, 2026
PHP min version7.4
Downloads998K

Community Trust

Rating98/100
Number of ratings32
Active installs50K
Developer Profile

المنتور فارسی Developer Profile

mohammadr3z

9 plugins · 51K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect المنتور فارسی

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/persian-elementor/assets/css/admin-options.css/wp-content/plugins/persian-elementor/assets/js/admin-options.js
Script Paths
/wp-content/plugins/persian-elementor/assets/js/admin-options.js

HTML / DOM Fingerprints

CSS Classes
persian-elementor-settingspersian-elementor-headerpersian-elementor-header-mainpersian-elementor-logopersian-elementor-header-title
Data Attributes
data-setting-id
JS Globals
persian_elementor_options
FAQ

Frequently Asked Questions about المنتور فارسی