Repeater Fields for Elementor Forms Security & Risk Analysis

wordpress.org/plugins/repeater-for-elementor

The Repeater Fields for Elementor Forms allow you to create one or more sets of fields that can be repeated.

700 active installs v2.2.7 PHP 5.2+ WP 2.0+ Updated Mar 30, 2026
elementor-formselementor-forms-fieldsrepeaterrepeater-fieldrepeater-form
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Repeater Fields for Elementor Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Repeater Fields for Elementor Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "repeater-for-elementor" v2.2.5 plugin exhibits a strong security posture based on the provided static analysis. The complete absence of dangerous functions, 100% use of prepared statements for SQL queries, and proper output escaping across all identified outputs are significant strengths. The plugin also demonstrates good practices by implementing nonce checks for its single AJAX handler. The vulnerability history being clean with zero known CVEs further reinforces this positive assessment, suggesting a mature and well-maintained codebase.

However, a notable concern is the complete lack of capability checks on its AJAX handler. While a nonce check is present, the absence of a capability check means that any authenticated user, regardless of their role or permissions, could potentially interact with this AJAX endpoint. This significantly broadens the potential attack surface, as malicious actors could leverage this if they find a way to exploit other vulnerabilities or gain unauthorized access to an authenticated session. The presence of file operations and external HTTP requests, while not inherently insecure, warrants careful scrutiny in a deeper audit to ensure they are implemented securely and do not introduce any vulnerabilities. The fact that there are no reported vulnerabilities and no taint analysis findings is encouraging, but the missing capability checks represent a potential oversight that could be exploited.

Key Concerns

  • AJAX handler lacks capability checks
Vulnerabilities
None known

Repeater Fields for Elementor Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Repeater Fields for Elementor Forms Release Timeline

v2.2.7Current
v2.2.6
v2.2.5
v2.2.4
v2.1.0
Code Analysis
Analyzed Mar 16, 2026

Repeater Fields for Elementor Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
38 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped38 total outputs
Attack Surface

Repeater Fields for Elementor Forms Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_yeekit_dismiss_notyyeekit\document.php:13
WordPress Hooks 19
actionelementor_pro/forms/validation/timefields\frontend.php:5
actionelementor_pro/forms/validation/telfields\frontend.php:6
actionelementor_pro/forms/validation/numberfields\frontend.php:7
actionadmin_enqueue_scriptsfields\frontend.php:10
actionelementor_pro/forms/validation/numberfields\frontend.php:12
actionwp_footerfields\repeater_end.php:11
actionwp_enqueue_scriptsfields\repeater_end.php:372
actionelementor/preview/initfields\repeater_end.php:373
actionwp_footerfields\repeater_start.php:11
actionelementor/preview/initfields\repeater_start.php:132
actionelementor_pro/forms/fields/registerrepeater-for-elementor.php:19
actionadmin_menuyeekit\document.php:10
actionadmin_enqueue_scriptsyeekit\document.php:11
filterfluentform_global_addonsyeekit\document.php:12
actionadmin_noticesyeekit\document.php:14
actionelementor/element/form/section_form_options/after_section_endyeekit\document.php:15
actionadmin_inityeekit\document.php:17
actionelementor/editor/after_enqueue_stylesyeekit\document.php:19
filterhttp_responseyeekit\document.php:208
Maintenance & Trust

Repeater Fields for Elementor Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 30, 2026
PHP min version5.2
Downloads7K

Community Trust

Rating80/100
Number of ratings3
Active installs700
Developer Profile

Repeater Fields for Elementor Forms Developer Profile

add-ons.org

59 plugins · 26K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
48 days
View full developer profile
Detection Fingerprints

How We Detect Repeater Fields for Elementor Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/repeater-for-elementor/fields/frontend.php/wp-content/plugins/repeater-for-elementor/fields/repeater_start.php/wp-content/plugins/repeater-for-elementor/fields/repeater_end.php/wp-content/plugins/repeater-for-elementor/yeekit/document.php/wp-content/plugins/repeater-for-elementor/libs/admin.js
Script Paths
/wp-content/plugins/repeater-for-elementor/libs/admin.js

HTML / DOM Fingerprints

Data Attributes
data-elementor-type="repeater"
JS Globals
elementor
Shortcode Output
<hr>
FAQ

Frequently Asked Questions about Repeater Fields for Elementor Forms