
Post Grid Addon for Elementor Security & Risk Analysis
wordpress.org/plugins/post-grid-elementor-addonAddon for the Elementor page builder to display posts in a grid. Useful for generating post grid from your blog posts with multiple options.
Is Post Grid Addon for Elementor Safe to Use in 2026?
Generally Safe
Score 99/100Post Grid Addon for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of post-grid-elementor-addon v2.0.23 reveals a strong adherence to some security best practices, with no detected dangerous functions, SQL injection risks, or file operations. The absence of detected taint flows and a generally good output escaping rate (86%) are positive indicators. However, the analysis also highlights significant concerns. Notably, there are zero capability checks and zero nonce checks across all entry points, which is a major red flag for potential unauthorized actions or privilege escalation if any of the entry points were to become exposed or if logic flaws exist within the existing code.
The vulnerability history is particularly concerning, with two known medium-severity CVEs, both of which are categorized as Cross-site Scripting (XSS). While currently unpatched CVEs are zero, the presence of past XSS vulnerabilities suggests that user input handling might be a weak point in this plugin, even if current static analysis didn't flag specific XSS flows. The lack of attack surface in the static analysis is a positive, but this could be misleading given the history of XSS vulnerabilities that might not always be obvious from static scans alone.
In conclusion, while the plugin demonstrates strengths in areas like SQL query sanitization and output escaping for most cases, the complete absence of capability and nonce checks, combined with a history of XSS vulnerabilities, presents a substantial risk. The plugin's security posture is a mix of good practices and potentially critical oversights, demanding careful review and prompt updates when new vulnerabilities are disclosed.
Key Concerns
- 0 capability checks on entry points
- 0 nonce checks on entry points
- 2 known medium severity CVEs in history
- 86% of output is properly escaped
Post Grid Addon for Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Post Grid Elementor Addon <= 2.0.18 - Authenticated (Contributor+) Stored Cross-Site Scripting
Post Grid Elementor Addon <= 2.0.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via title_tag
Post Grid Addon for Elementor Code Analysis
Output Escaping
Post Grid Addon for Elementor Attack Surface
WordPress Hooks 12
Maintenance & Trust
Post Grid Addon for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
Post Grid Addon for Elementor Alternatives
Ultimate Post Kit Addons for Elementor
ultimate-post-kit
Build your blogs and news sites with a feature-rich Elementor addon, offering 100+ elements for engaging layouts.
EleSpare – News, Magazine and Blog Addons for Elementor
elespare
EleSpare provides pre-designed templates, header/footer builders, and various post layouts for creating stunning news, magazine, and blog sites with E …
BlogLentor – Blog Designer Pack for Elementor
bloglentor-for-elementor
Design and modify your blog with creative layouts. You can easily design your blog posts with slider, Carousel and different skins with pagination.
News Element Elementor Blog Magazine
news-element
Create News, Magazine and Blogs with grid, slider, hero, header-footer etc.
Blog News Addons For Elementor (News, Magazine and Blog Addons)
blognews-for-elementor
Build news, magazine & blog sites with BlogNews for Elementor. 50+ widgets, 20+ templates, header/footer builder. No coding required!
Post Grid Addon for Elementor Developer Profile
6 plugins · 121K total installs
How We Detect Post Grid Addon for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-grid-elementor-addon/assets/css/main.cssHTML / DOM Fingerprints
post-grid-widget