Post Submissions for Elementor Forms Security & Risk Analysis

wordpress.org/plugins/post-submissions-for-elementor-forms

Allow users to submit WordPress posts directly from Elementor Forms. Easy setup, flexible, and developer-friendly.

60 active installs v1.0.0 PHP + WP 2.0+ Updated Nov 28, 2025
blog-postelementorformsfrontend-postuser-submission
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Post Submissions for Elementor Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Post Submissions for Elementor Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The 'post-submissions-for-elementor-forms' plugin version 1.0.0 demonstrates a strong security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and 100% proper output escaping indicate a commitment to secure coding practices. The plugin also correctly handles its single AJAX entry point with a nonce check and has no recorded vulnerabilities, further bolstering its perceived security.

However, there are a few areas that warrant attention. The lack of capability checks on the AJAX handler, while protected by a nonce, means that any authenticated user, regardless of their role, can trigger this functionality. The presence of two external HTTP requests without further context could potentially introduce risks if the target URLs are untrusted or if the data sent/received is not properly handled. Furthermore, the lack of taint analysis results for version 1.0.0 doesn't definitively prove the absence of all taint-related vulnerabilities, only that none were detected by the specific analysis performed.

Overall, the plugin appears to be built with good security principles in mind, especially concerning direct code execution and data output. The primary areas for potential improvement lie in refining access control beyond nonce checks and ensuring secure handling of external requests. The clean vulnerability history is a significant positive indicator, suggesting a well-maintained and secure plugin over time.

Key Concerns

  • AJAX handler without capability checks
  • External HTTP requests present
Vulnerabilities
None known

Post Submissions for Elementor Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Post Submissions for Elementor Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
33 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped33 total outputs
Attack Surface

Post Submissions for Elementor Forms Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_yeekit_dismiss_notyyeekit\document.php:13
WordPress Hooks 9
actionelementor_pro/forms/actions/registerpost-submissions-for-elementor-forms.php:28
actionadmin_menuyeekit\document.php:10
actionadmin_enqueue_scriptsyeekit\document.php:11
filterfluentform_global_addonsyeekit\document.php:12
actionadmin_noticesyeekit\document.php:14
actionelementor/element/form/section_form_options/after_section_endyeekit\document.php:15
actionadmin_inityeekit\document.php:17
actionelementor/editor/after_enqueue_stylesyeekit\document.php:19
filterhttp_responseyeekit\document.php:208
Maintenance & Trust

Post Submissions for Elementor Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 28, 2025
PHP min version
Downloads432

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

Post Submissions for Elementor Forms Developer Profile

add-ons.org

55 plugins · 26K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
47 days
View full developer profile
Detection Fingerprints

How We Detect Post Submissions for Elementor Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/post-submissions-for-elementor-forms/backend/css/backend.css/wp-content/plugins/post-submissions-for-elementor-forms/backend/js/backend.js/wp-content/plugins/post-submissions-for-elementor-forms/elementor/widgets/post-submit-form.css/wp-content/plugins/post-submissions-for-elementor-forms/elementor/widgets/post-submit-form.js
Script Paths
/wp-content/plugins/post-submissions-for-elementor-forms/backend/js/backend.js/wp-content/plugins/post-submissions-for-elementor-forms/elementor/widgets/post-submit-form.js
Version Parameters
post-submissions-for-elementor-forms/backend/css/backend.css?ver=post-submissions-for-elementor-forms/backend/js/backend.js?ver=post-submissions-for-elementor-forms/elementor/widgets/post-submit-form.css?ver=post-submissions-for-elementor-forms/elementor/widgets/post-submit-form.js?ver=

HTML / DOM Fingerprints

CSS Classes
yeekit_addons_listyee-installyee-pro
HTML Comments
<!-- Plugin Name: Post Submissions for Elementor Forms --><!-- Allow users to submit WordPress posts directly from Elementor Forms --><!-- Version: 1.0.0 -->
Data Attributes
data-elementor-device-modedata-settings
JS Globals
YEEKIT_EL_PS_PLUGIN_PATHYEEKIT_EL_PS_PLUGIN_URLyeekit_document_addonsYeekit_Document_Addons
FAQ

Frequently Asked Questions about Post Submissions for Elementor Forms