Prime Addons for Elementor Security & Risk Analysis

wordpress.org/plugins/prime-addons-for-elementor

Elementor widgets and extensions.

100 active installs v2.0.3 PHP 7.4+ WP 6.0+ Updated Sep 11, 2025
elementor-addonelementor-widgetflip-boxpost-carouselpost-grid
99
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 19, 2025
Safety Verdict

Is Prime Addons for Elementor Safe to Use in 2026?

Generally Safe

Score 99/100

Prime Addons for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 19, 2025Updated 6mo ago
Risk Assessment

The prime-addons-for-elementor plugin version 2.0.3 exhibits a generally good security posture based on the provided static analysis. The plugin demonstrates strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and properly escaping a high percentage of its output. The absence of dangerous functions, file operations, external HTTP requests, and taint flows with unsanitized paths are all positive indicators. However, a notable concern is the lack of nonce and capability checks across all identified entry points. While the static analysis shows zero unprotected entry points, the absence of these fundamental security checks on the single shortcode entry point is a significant weakness that could be exploited if not properly handled internally. The vulnerability history, with one medium-severity CVE related to Improper Access Control, further highlights the importance of robust access control mechanisms. The fact that the CVE is not currently unpatched is a positive sign, but the historical presence of such an issue, coupled with the lack of explicit capability checks in the current version, suggests a potential recurring risk.

Key Concerns

  • Missing capability checks on entry points
  • Missing nonce checks on entry points
  • History of medium severity vulnerability
  • Percentage of unescaped output
Vulnerabilities
1

Prime Addons for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-13855medium · 4.3Improper Access Control

Prime Addons for Elementor <= 2.0.1 - Authenticated (Contributor+) Insecure Direct Object Reference via pae_global_block Shortcode

Feb 19, 2025 Patched in 2.0.2 (22d)
Code Analysis
Analyzed Mar 16, 2026

Prime Addons for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
65
392 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped457 total outputs
Attack Surface

Prime Addons for Elementor Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[pae_global_block] includes\global-blocks\class-global-blocks.php:170
WordPress Hooks 43
actionelementor/element/after_section_endincludes\controls\opacity.php:62
actionelementor/element/after_section_endincludes\controls\parallax.php:81
actionelementor/frontend/element/before_renderincludes\controls\parallax.php:97
actionelementor/frontend/widget/before_renderincludes\controls\parallax.php:98
actionelementor/frontend/after_register_stylesincludes\elements\class-elements.php:54
actionwp_enqueue_scriptsincludes\elements\class-elements.php:55
actionelementor/widgets/widgets_registeredincludes\elements\class-elements.php:56
actionelementor/elements/categories_registeredincludes\elements\class-elements.php:57
actioninitincludes\elements\class-elements.php:58
actionpae_action_blog_grid_controlsincludes\elements\class-elements.php:61
actionpae_action_blog_masonry_controlsincludes\elements\class-elements.php:62
actionpae_action_blog_standard_controlsincludes\elements\class-elements.php:63
actionpae_action_global_block_slider_controlsincludes\elements\class-elements.php:66
actionpae_action_global_block_slider_controlsincludes\elements\class-elements.php:67
actionpae_action_picture_slider_controlsincludes\elements\class-elements.php:70
actionpae_action_picture_slider_controlsincludes\elements\class-elements.php:71
actionpae_action_post_slider_controlsincludes\elements\class-elements.php:74
actionpae_action_post_slider_controlsincludes\elements\class-elements.php:75
actionpae_action_post_slider_style_controlsincludes\elements\class-elements.php:76
actionpae_action_post_carousel_after_post_settings_controlsincludes\elements\class-elements.php:79
actionpae_action_post_carousel_after_layout_settings_controlsincludes\elements\class-elements.php:80
actionpae_action_post_carousel_after_excerpt_style_controlsincludes\elements\class-elements.php:81
actionpae_action_woo_product_carousel_after_layout_settings_controlsincludes\elements\class-elements.php:84
actionpae_action_woo_product_carousel_after_icon_style_controlsincludes\elements\class-elements.php:85
actionpae_action_edd_product_carousel_after_layout_settings_controlsincludes\elements\class-elements.php:88
actionpae_action_edd_product_carousel_after_icon_style_controlsincludes\elements\class-elements.php:89
actionpae_action_lp_course_carousel_after_layout_settings_controlsincludes\elements\class-elements.php:92
actionpae_action_lp_course_carousel_after_icon_style_controlsincludes\elements\class-elements.php:93
actionpae_action_picture_carousel_after_layout_settings_controlsincludes\elements\class-elements.php:96
actionpae_action_picture_carousel_after_overlay_style_controlsincludes\elements\class-elements.php:97
actionpae_action_testimonial_carousel_after_layout_settings_controlsincludes\elements\class-elements.php:100
actionpae_action_testimonial_carousel_after_column_style_controlsincludes\elements\class-elements.php:101
actioninitincludes\global-blocks\class-global-blocks.php:161
actioninitincludes\global-blocks\class-global-blocks.php:162
actionelementor/initincludes\global-blocks\class-global-blocks.php:163
actionadd_meta_boxesincludes\global-blocks\class-global-blocks.php:164
filtersingle_templateincludes\global-blocks\class-global-blocks.php:165
actionwidgets_initincludes\global-blocks\widget.php:23
actioninitprime-addons-for-elementor.php:77
actionadmin_noticesprime-addons-for-elementor.php:88
actionadmin_noticesprime-addons-for-elementor.php:94
actionadmin_noticesprime-addons-for-elementor.php:100
actionadmin_initprime-addons-for-elementor.php:105
Maintenance & Trust

Prime Addons for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 11, 2025
PHP min version7.4
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Prime Addons for Elementor Developer Profile

Nilambar Sharma

9 plugins · 9K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
22 days
View full developer profile
Detection Fingerprints

How We Detect Prime Addons for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/prime-addons-for-elementor/assets/css/prime-addons-elementor.css/wp-content/plugins/prime-addons-for-elementor/assets/js/prime-addons-elementor.js/wp-content/plugins/prime-addons-for-elementor/assets/css/editor.css/wp-content/plugins/prime-addons-for-elementor/assets/js/editor.js
Script Paths
/wp-content/plugins/prime-addons-for-elementor/assets/js/prime-addons-elementor.js/wp-content/plugins/prime-addons-for-elementor/assets/js/editor.js
Version Parameters
prime-addons-for-elementor/assets/css/prime-addons-elementor.css?ver=prime-addons-for-elementor/assets/js/prime-addons-elementor.js?ver=prime-addons-for-elementor/assets/css/editor.css?ver=prime-addons-for-elementor/assets/js/editor.js?ver=

HTML / DOM Fingerprints

CSS Classes
pae-sectionpae-columnpae-widgetprime-addons-elementor-titleprime-addons-elementor-description
Data Attributes
data-pae-settings
JS Globals
PrimeAddonsElementorFrontendPAEFrontend
FAQ

Frequently Asked Questions about Prime Addons for Elementor