Post Grid Addon for Elementor Security & Risk Analysis

wordpress.org/plugins/post-grid-elementor-addon

Addon for the Elementor page builder to display posts in a grid. Useful for generating post grid from your blog posts with multiple options.

20K active installs v2.0.23 PHP 5.6+ WP 5.0+ Updated Dec 5, 2025
blog-post-gridelementorelementor-addonspost-gridpost-grid-for-elementor
99
A · Safe
CVEs total2
Unpatched0
Last CVEDec 30, 2024
Safety Verdict

Is Post Grid Addon for Elementor Safe to Use in 2026?

Generally Safe

Score 99/100

Post Grid Addon for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Dec 30, 2024Updated 3mo ago
Risk Assessment

The static analysis of post-grid-elementor-addon v2.0.23 reveals a strong adherence to some security best practices, with no detected dangerous functions, SQL injection risks, or file operations. The absence of detected taint flows and a generally good output escaping rate (86%) are positive indicators. However, the analysis also highlights significant concerns. Notably, there are zero capability checks and zero nonce checks across all entry points, which is a major red flag for potential unauthorized actions or privilege escalation if any of the entry points were to become exposed or if logic flaws exist within the existing code.

The vulnerability history is particularly concerning, with two known medium-severity CVEs, both of which are categorized as Cross-site Scripting (XSS). While currently unpatched CVEs are zero, the presence of past XSS vulnerabilities suggests that user input handling might be a weak point in this plugin, even if current static analysis didn't flag specific XSS flows. The lack of attack surface in the static analysis is a positive, but this could be misleading given the history of XSS vulnerabilities that might not always be obvious from static scans alone.

In conclusion, while the plugin demonstrates strengths in areas like SQL query sanitization and output escaping for most cases, the complete absence of capability and nonce checks, combined with a history of XSS vulnerabilities, presents a substantial risk. The plugin's security posture is a mix of good practices and potentially critical oversights, demanding careful review and prompt updates when new vulnerabilities are disclosed.

Key Concerns

  • 0 capability checks on entry points
  • 0 nonce checks on entry points
  • 2 known medium severity CVEs in history
  • 86% of output is properly escaped
Vulnerabilities
2

Post Grid Addon for Elementor Security Vulnerabilities

CVEs by Year

2 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-56268medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Post Grid Elementor Addon <= 2.0.18 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 30, 2024 Patched in 2.0.19 (10d)
CVE-2024-34789medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Post Grid Elementor Addon <= 2.0.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via title_tag

May 17, 2024 Patched in 2.0.17 (4d)
Code Analysis
Analyzed Mar 16, 2026

Post Grid Addon for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped14 total outputs
Attack Surface

Post Grid Addon for Elementor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionwp_welcome_initinc\admin.php:10
actionelementor/frontend/after_enqueue_stylesplugin.php:130
actionelementor/widgets/registerplugin.php:133
actionelementor/elements/categories_registeredplugin.php:135
actioninitpost-grid-elementor-addon.php:81
actionplugins_loadedpost-grid-elementor-addon.php:84
actionadmin_noticespost-grid-elementor-addon.php:116
actionadmin_noticespost-grid-elementor-addon.php:122
actionadmin_noticespost-grid-elementor-addon.php:128
actionadmin_initpost-grid-elementor-addon.php:132
filterexcerpt_morewidgets\post-grid.php:1258
filterexcerpt_lengthwidgets\post-grid.php:1259
Maintenance & Trust

Post Grid Addon for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 5, 2025
PHP min version5.6
Downloads503K

Community Trust

Rating96/100
Number of ratings73
Active installs20K
Developer Profile

Post Grid Addon for Elementor Developer Profile

hookandhook

6 plugins · 121K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
478 days
View full developer profile
Detection Fingerprints

How We Detect Post Grid Addon for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/post-grid-elementor-addon/assets/css/main.css

HTML / DOM Fingerprints

CSS Classes
post-grid-widget
FAQ

Frequently Asked Questions about Post Grid Addon for Elementor