Pro Addons For Elementor | Premium Addons Security & Risk Analysis

wordpress.org/plugins/pro-addons-for-elementor

Pro Addons For Elementor is an essential addon for Elementor that provides the Elementor Pro features and functionality for free.

200 active installs v1.9.0 PHP 5.6+ WP 4.0.0+ Updated May 22, 2025
elementorelementor-addonselementor-elementspro-addonswidgets
99
A · Safe
CVEs total1
Unpatched0
Last CVENov 8, 2024
Safety Verdict

Is Pro Addons For Elementor | Premium Addons Safe to Use in 2026?

Generally Safe

Score 99/100

Pro Addons For Elementor | Premium Addons has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 8, 2024Updated 10mo ago
Risk Assessment

The "pro-addons-for-elementor" plugin version 1.9.0 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and a high percentage of properly escaped output, significant concerns arise from its attack surface. Specifically, the plugin exposes two entry points without authentication or proper permission checks: one AJAX handler and one REST API route. This is a critical oversight that could allow unauthenticated attackers to interact with potentially sensitive plugin functionality.

Taint analysis indicates no critical or high-severity vulnerabilities, which is a positive sign. However, the presence of four unsanitized paths in taint analysis, even without critical severity, suggests potential areas for subtle vulnerabilities if not handled with extreme care. The plugin's vulnerability history includes a medium-severity Cross-Site Scripting (XSS) vulnerability in the past, indicating that input sanitization and output escaping, despite being largely effective, are areas that have historically been problematic and require ongoing vigilance.

In conclusion, the plugin has strengths in its database query handling and output escaping. However, the unprotected entry points represent a significant and immediate risk. The history of XSS vulnerabilities, coupled with the identified unsanitized paths, suggests that while the core implementation is relatively secure, the handling of user-supplied input and accessible endpoints needs to be rigorously reviewed and secured. The lack of unpatched vulnerabilities is encouraging, but the exposed attack surface and past XSS issues warrant caution.

Key Concerns

  • Unprotected AJAX handler
  • Unprotected REST API route
  • Taint analysis: 4 unsanitized paths
  • Past medium XSS vulnerability
Vulnerabilities
1

Pro Addons For Elementor | Premium Addons Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-51812medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Pro Addons For Elementor <= 1.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 8, 2024 Patched in 1.6.0 (7d)
Code Analysis
Analyzed Mar 16, 2026

Pro Addons For Elementor | Premium Addons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
24
138 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

85% escaped162 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
render (includes\widgets\pafe-widget-dynamic-text.php:500)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Pro Addons For Elementor | Premium Addons Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 1

authwp_ajax_pafe_dismiss_review_notificationincludes\PAFE_admin_class.php:51

REST API Routes 1

GET/wp-json/pafe/v1get_post_meta/(?P<id>[\d]+)/(?P<key>[\a-zA-Z0-9-]+)includes\plugin.php:291
WordPress Hooks 21
actioninitincludes\PAFE_admin_class.php:30
actionadd_meta_boxesincludes\PAFE_admin_class.php:33
actionsave_postincludes\PAFE_admin_class.php:36
filtertemplate_includeincludes\PAFE_admin_class.php:39
actionwp_after_admin_bar_renderincludes\PAFE_admin_class.php:42
actionadmin_noticesincludes\PAFE_admin_class.php:48
actionelementor/initincludes\plugin.php:119
actionadmin_noticesincludes\plugin.php:140
actionadmin_noticesincludes\plugin.php:149
actionadmin_noticesincludes\plugin.php:158
actionrest_api_initincludes\plugin.php:255
actionelementor/documents/register_controlsincludes\plugin.php:258
actionelementor/widgets/registerincludes\plugin.php:261
actionwp_enqueue_scriptsincludes\plugin.php:264
actionelementor/editor/after_enqueue_stylesincludes\plugin.php:267
actionwp_headincludes\plugin.php:271
actionwp_headincludes\plugin.php:274
actionwp_footerincludes\plugin.php:277
actionwp_footerincludes\plugin.php:280
filterscript_loader_tagincludes\plugin.php:283
actionplugins_loadedpro-addons-for-elementor.php:50
Maintenance & Trust

Pro Addons For Elementor | Premium Addons Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 22, 2025
PHP min version5.6
Downloads9K

Community Trust

Rating100/100
Number of ratings2
Active installs200
Developer Profile

Pro Addons For Elementor | Premium Addons Developer Profile

Wasim

2 plugins · 2K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Pro Addons For Elementor | Premium Addons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pro-addons-for-elementor/assets/css/pafe-editor-styles.css/wp-content/plugins/pro-addons-for-elementor/assets/css/pafe-frontend.css/wp-content/plugins/pro-addons-for-elementor/assets/js/pafe-editor-scripts.js/wp-content/plugins/pro-addons-for-elementor/assets/js/pafe-frontend.js
Script Paths
/wp-content/plugins/pro-addons-for-elementor/assets/js/pafe-editor-scripts.js/wp-content/plugins/pro-addons-for-elementor/assets/js/pafe-frontend.js
Version Parameters
pro-addons-for-elementor/assets/css/pafe-editor-styles.css?ver=pro-addons-for-elementor/assets/css/pafe-frontend.css?ver=pro-addons-for-elementor/assets/js/pafe-editor-scripts.js?ver=pro-addons-for-elementor/assets/js/pafe-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
pafe-editor-stylespafe-frontend
HTML Comments
<!-- Pro Addons For Elementor --><!-- End Pro Addons For Elementor -->
Data Attributes
data-pafe-custom-cssdata-pafe-custom-jsdata-pafe-header-codedata-pafe-footer-codedata-pafe-template-custom-cssdata-pafe-template-header-code+1 more
JS Globals
PAFE_ADMIN_Settings
REST Endpoints
/wp-json/pafe/v1/admin/settings
FAQ

Frequently Asked Questions about Pro Addons For Elementor | Premium Addons