Restaurant & Cafe Addon for Elementor Security & Risk Analysis

wordpress.org/plugins/restaurant-cafe-addon-for-elementor

Restaurant & Cafe Addon for Elementor is an Elementor Addons for Restaurant Websites.

2K active installs v1.6.4 PHP 7.4+ WP 6.0+ Updated Mar 10, 2025
addonscafeelementorfoodrestaurant
89
A · Safe
CVEs total8
Unpatched0
Last CVEDec 11, 2024
Safety Verdict

Is Restaurant & Cafe Addon for Elementor Safe to Use in 2026?

Generally Safe

Score 89/100

Restaurant & Cafe Addon for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

8 known CVEsLast CVE: Dec 11, 2024Updated 1yr ago
Risk Assessment

The plugin "restaurant-cafe-addon-for-elementor" v1.6.4 exhibits a mixed security posture. On the positive side, the static analysis reveals good coding practices in several areas. All identified AJAX entry points have nonce checks and capability checks, indicating a strong effort to prevent unauthorized actions. Furthermore, all SQL queries utilize prepared statements, and a high percentage of output is properly escaped, which significantly mitigates risks like SQL injection and reflected/stored cross-site scripting. The absence of critical or high-severity taint flows suggests that direct data manipulation vulnerabilities are unlikely within the analyzed code paths.

However, the plugin's vulnerability history presents a significant concern. With 8 known CVEs, including 7 medium and 1 low severity issues, it indicates a pattern of past security weaknesses. The common vulnerability types such as Authorization Bypass, Cross-Site Scripting, Missing Authorization, and CSRF suggest recurring fundamental security flaws. While there are currently no unpatched vulnerabilities, this history necessitates vigilance, as past issues can indicate a propensity for future similar vulnerabilities if underlying coding practices are not consistently reinforced. The last vulnerability was also very recent, which is a point of caution.

In conclusion, while the current version's static analysis shows commendable security controls for its entry points and data handling, the historical prevalence and types of vulnerabilities cannot be ignored. The plugin has strengths in its current code's defenses against common web attacks, but its past record suggests a higher overall risk profile that requires careful monitoring and potentially more robust security auditing.

Key Concerns

  • 8 known CVEs with 7 medium, 1 low
  • Recent vulnerability (2024-12-11)
  • Bundled outdated library (Freemius v1.0)
  • 87% of output properly escaped (13% not)
Vulnerabilities
8

Restaurant & Cafe Addon for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
3 CVEs in 2023
2023
4 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
7
Low
1

8 total CVEs

CVE-2024-54316medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Restaurant & Cafe Addon for Elementor <= 1.5.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 11, 2024 Patched in 1.5.9 (9d)
CVE-2024-10780medium · 4.3Authorization Bypass Through User-Controlled Key

Restaurant & Cafe Addon for Elementor <= 1.5.9 - Authenticated (Contributor+) Post Disclosure

Nov 27, 2024 Patched in 1.6.0 (1d)
CVE-2024-51581medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Restaurant & Cafe Addon for Elementor <= 1.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

Oct 31, 2024 Patched in 1.5.7 (7d)
CVE-2024-44032medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Restaurant & Cafe Addon for Elementor <= 1.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 24, 2024 Patched in 1.5.6 (9d)
CVE-2023-47826low · 3.1Missing Authorization

Restaurant & Cafe Addon for Elementor <= 1.5.3 - Missing Authorization via multiple AJAX functions

Nov 16, 2023 Patched in 1.5.4 (68d)

Restaurant & Cafe Addon for Elementor <= 1.5.2 - Missing Authorization

Nov 14, 2023 Patched in 1.5.3 (70d)

Restaurant & Cafe Addon for Elementor <= 1.5.2 - Cross-Site Request Forgery

Nov 14, 2023 Patched in 1.5.3 (70d)
CVE-2022-4974medium · 6.3Missing Authorization

Freemius SDK <= 2.4.2 - Missing Authorization Checks

Mar 4, 2022 Patched in 1.4.6 (1260d)
Code Analysis
Analyzed Mar 16, 2026

Restaurant & Cafe Addon for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
100
642 escaped
Nonce Checks
4
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

87% escaped742 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
rctl_bw_toggle_submit_func (elementor\narep-admin-functions.php:20)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Restaurant & Cafe Addon for Elementor Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_rcafe_bw_settings_saveelementor\narep-admin-functions.php:18
authwp_ajax_rctl_bw_toggle_submitelementor\narep-admin-functions.php:26
authwp_ajax_rcafe_uw_settings_saveelementor\narep-admin-functions.php:43
authwp_ajax_rctl_uw_toggle_submitelementor\narep-admin-functions.php:51
WordPress Hooks 30
actionplugins_loadedelementor\em-setup.php:33
actionelementor/frontend/after_enqueue_scriptselementor\em-setup.php:36
actionelementor/editor/before_enqueue_scriptselementor\em-setup.php:40
actionadmin_noticeselementor\em-setup.php:159
actionadmin_noticeselementor\em-setup.php:165
actionelementor/elements/categories_registeredelementor\em-setup.php:173
actionelementor/elements/categories_registeredelementor\em-setup.php:174
actionelementor/widgets/widgets_registeredelementor\em-setup.php:177
actionelementor/widgets/widgets_registeredelementor\em-setup.php:178
actionwp_dashboard_setupelementor\em-setup.php:180
actionafter_switch_themeelementor\em-setup.php:299
actionpt-ocdi/after_content_import_executionelementor\em-setup.php:307
filterexcerpt_lengthelementor\em-setup.php:324
filterexcerpt_moreelementor\em-setup.php:350
actionnarestaurant_woocommerce_after_shop_loop_itemelementor\em-setup.php:417
actioninitelementor\em-setup.php:444
filterconnect_urlrestaurant-cafe-addon-for-elementor.php:60
filterafter_skip_urlrestaurant-cafe-addon-for-elementor.php:61
filterafter_connect_urlrestaurant-cafe-addon-for-elementor.php:62
filterafter_pending_connect_urlrestaurant-cafe-addon-for-elementor.php:63
actionadmin_enqueue_scriptsrestaurant-cafe-addon-for-elementor.php:96
actionadmin_menurestaurant-cafe-addon-for-elementor.php:105
actioninitrestaurant-cafe-addon-for-elementor.php:153
actionadmin_noticesrestaurant-cafe-addon-for-elementor.php:159
actionplugins_loadedrestaurant-cafe-addon-for-elementor.php:164
actionadmin_noticesrestaurant-cafe-addon-for-elementor.php:184
actionadmin_noticesrestaurant-cafe-addon-for-elementor.php:202
actionelementor/editor/before_enqueue_scriptsrestaurant-cafe-addon-for-elementor.php:215
actionelementor/frontend/after_enqueue_scriptsrestaurant-cafe-addon-for-elementor.php:236
actionwp_enqueue_scriptsrestaurant-cafe-addon-for-elementor.php:505
Maintenance & Trust

Restaurant & Cafe Addon for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 10, 2025
PHP min version7.4
Downloads49K

Community Trust

Rating96/100
Number of ratings6
Active installs2K
Developer Profile

Restaurant & Cafe Addon for Elementor Developer Profile

nicheaddons

7 plugins · 19K total installs

75
trust score
Avg Security Score
82/100
Avg Patch Time
74 days
View full developer profile
Detection Fingerprints

How We Detect Restaurant & Cafe Addon for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/restaurant-cafe-addon-for-elementor/assets/css/themify-icons.min.css/wp-content/plugins/restaurant-cafe-addon-for-elementor/assets/css/admin-styles.css/wp-content/plugins/restaurant-cafe-addon-for-elementor/assets/js/repeatable-fields.js/wp-content/plugins/restaurant-cafe-addon-for-elementor/assets/js/admin-scripts.js
Script Paths
/wp-content/plugins/restaurant-cafe-addon-for-elementor/assets/js/repeatable-fields.js/wp-content/plugins/restaurant-cafe-addon-for-elementor/assets/js/admin-scripts.js
Version Parameters
restaurant-cafe-addon-for-elementor/assets/css/themify-icons.min.css?ver=restaurant-cafe-addon-for-elementor/assets/css/admin-styles.css?ver=restaurant-cafe-addon-for-elementor/assets/js/repeatable-fields.js?ver=restaurant-cafe-addon-for-elementor/assets/js/admin-scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
narep-admin-page
HTML Comments
<!-- Pro Codes --><!-- PLUGIN SELF PATH --><!-- Enqueue Files for BackEnd --><!-- Admin Pages -->+9 more
Data Attributes
data-elementor-iddata-elementor-post-type
JS Globals
NAREP_VERSIONNAREP_URL
FAQ

Frequently Asked Questions about Restaurant & Cafe Addon for Elementor