
Pro Addons For Elementor | Premium Addons Security & Risk Analysis
wordpress.org/plugins/pro-addons-for-elementorPro Addons For Elementor is an essential addon for Elementor that provides the Elementor Pro features and functionality for free.
Is Pro Addons For Elementor | Premium Addons Safe to Use in 2026?
Generally Safe
Score 99/100Pro Addons For Elementor | Premium Addons has a strong security track record. Known vulnerabilities have been patched promptly.
The "pro-addons-for-elementor" plugin version 1.9.0 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and a high percentage of properly escaped output, significant concerns arise from its attack surface. Specifically, the plugin exposes two entry points without authentication or proper permission checks: one AJAX handler and one REST API route. This is a critical oversight that could allow unauthenticated attackers to interact with potentially sensitive plugin functionality.
Taint analysis indicates no critical or high-severity vulnerabilities, which is a positive sign. However, the presence of four unsanitized paths in taint analysis, even without critical severity, suggests potential areas for subtle vulnerabilities if not handled with extreme care. The plugin's vulnerability history includes a medium-severity Cross-Site Scripting (XSS) vulnerability in the past, indicating that input sanitization and output escaping, despite being largely effective, are areas that have historically been problematic and require ongoing vigilance.
In conclusion, the plugin has strengths in its database query handling and output escaping. However, the unprotected entry points represent a significant and immediate risk. The history of XSS vulnerabilities, coupled with the identified unsanitized paths, suggests that while the core implementation is relatively secure, the handling of user-supplied input and accessible endpoints needs to be rigorously reviewed and secured. The lack of unpatched vulnerabilities is encouraging, but the exposed attack surface and past XSS issues warrant caution.
Key Concerns
- Unprotected AJAX handler
- Unprotected REST API route
- Taint analysis: 4 unsanitized paths
- Past medium XSS vulnerability
Pro Addons For Elementor | Premium Addons Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Pro Addons For Elementor <= 1.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Pro Addons For Elementor | Premium Addons Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Pro Addons For Elementor | Premium Addons Attack Surface
AJAX Handlers 1
REST API Routes 1
WordPress Hooks 21
Maintenance & Trust
Pro Addons For Elementor | Premium Addons Maintenance & Trust
Maintenance Signals
Community Trust
Pro Addons For Elementor | Premium Addons Alternatives
Qi Addons For Elementor
qi-addons-for-elementor
Qi Addons for Elementor is a comprehensive library of 60+ custom, flexible & easily styled Elementor widgets developed by Qode Interactive.
MT Addons for Elementor
mt-addons-for-elementor
MT Addons for Elementor with 50+ widgets, crafted by ModelTheme for dynamic, stylish website creation.
ACF Post Object Elementor List Widget
acf-post-object-elementor-list-widget
A WordPress Plugin that adds the ability to display the contents of an ACF Post Object field as a list of post links.
Wadi Addons for Elementor
wadi-addons-for-elementor
Wadi Addons for Elementor Page Builder provides a collection of quality Elementor Widgets which powers your Elementor Page Builder and takes your page …
Balcomsoft Elementor Addons
balcomsoft-elementor-addons
Minimum Requirements WordPress 4.4 or greater WooCommerce 3.0.0 or greater Elementor 3.8.0 or greater Visit the Elementor server requirements docu …
Pro Addons For Elementor | Premium Addons Developer Profile
2 plugins · 2K total installs
How We Detect Pro Addons For Elementor | Premium Addons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pro-addons-for-elementor/assets/css/pafe-editor-styles.css/wp-content/plugins/pro-addons-for-elementor/assets/css/pafe-frontend.css/wp-content/plugins/pro-addons-for-elementor/assets/js/pafe-editor-scripts.js/wp-content/plugins/pro-addons-for-elementor/assets/js/pafe-frontend.js/wp-content/plugins/pro-addons-for-elementor/assets/js/pafe-editor-scripts.js/wp-content/plugins/pro-addons-for-elementor/assets/js/pafe-frontend.jspro-addons-for-elementor/assets/css/pafe-editor-styles.css?ver=pro-addons-for-elementor/assets/css/pafe-frontend.css?ver=pro-addons-for-elementor/assets/js/pafe-editor-scripts.js?ver=pro-addons-for-elementor/assets/js/pafe-frontend.js?ver=HTML / DOM Fingerprints
pafe-editor-stylespafe-frontend<!-- Pro Addons For Elementor --><!-- End Pro Addons For Elementor -->data-pafe-custom-cssdata-pafe-custom-jsdata-pafe-header-codedata-pafe-footer-codedata-pafe-template-custom-cssdata-pafe-template-header-code+1 morePAFE_ADMIN_Settings/wp-json/pafe/v1/admin/settings