Restrict Elementor Widgets, Columns and Sections Security & Risk Analysis

wordpress.org/plugins/restrict-elementor-widgets

Restrict Elementor Widgets based on different conditions. Works for any widgets from any plugins.

500 active installs v1.12 PHP 7.4+ WP 6.0+ Updated Jun 3, 2025
lock-elementorrestrict-elementorrestrict-widget
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEDec 13, 2025
Safety Verdict

Is Restrict Elementor Widgets, Columns and Sections Safe to Use in 2026?

Mostly Safe

Score 78/100

Restrict Elementor Widgets, Columns and Sections is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Dec 13, 2025Updated 10mo ago
Risk Assessment

The 'restrict-elementor-widgets' plugin, version 1.12, presents a mixed security posture. While the static analysis shows no critical or high-severity code signals like dangerous functions, raw SQL queries, or unsanitized taint flows, there are areas for improvement. The plugin has a relatively small attack surface with no exposed AJAX handlers or REST API routes without authentication. However, the low percentage of properly escaped output (54%) is a notable concern, indicating potential for Cross-Site Scripting (XSS) vulnerabilities, especially if the inputs are user-controlled.

The plugin's vulnerability history is a significant red flag. With one known medium-severity CVE and one currently unpatched vulnerability, the pattern suggests a recurring issue with missing authorization. This is further corroborated by the vulnerability history mentioning 'Missing Authorization' as a common type. The recent date of the last vulnerability (2025-12-13) implies that this is an ongoing problem that has not been adequately addressed in recent versions.

In conclusion, while the code itself appears to avoid some common pitfalls like raw SQL and dangerous functions, the persistent history of authorization vulnerabilities and the high rate of unescaped output pose significant risks. The presence of an unpatched CVE is a critical issue that requires immediate attention.

Key Concerns

  • Unpatched medium severity CVE
  • Missing authorization vulnerability history
  • Low output escaping percentage
  • No capability checks
  • No nonce checks
Vulnerabilities
1

Restrict Elementor Widgets, Columns and Sections Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-64244medium · 4.3Missing Authorization

Restrict Elementor Widgets, Columns and Sections <= 1.12 - Missing Authorization

Dec 13, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Restrict Elementor Widgets, Columns and Sections Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

54% escaped13 total outputs
Attack Surface

Restrict Elementor Widgets, Columns and Sections Attack Surface

Entry Points0
Unprotected0

Scheduled Events 1

restrict-elementor-widgets_daily
Maintenance & Trust

Restrict Elementor Widgets, Columns and Sections Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 3, 2025
PHP min version7.4
Downloads11K

Community Trust

Rating84/100
Number of ratings5
Active installs500
Developer Profile

Restrict Elementor Widgets, Columns and Sections Developer Profile

Codexpert, Inc

10 plugins · 41K total installs

75
trust score
Avg Security Score
81/100
Avg Patch Time
39 days
View full developer profile
Detection Fingerprints

How We Detect Restrict Elementor Widgets, Columns and Sections

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/restrict-elementor-widgets/assets/css/rew-admin.css/wp-content/plugins/restrict-elementor-widgets/assets/css/rew-frontend.css/wp-content/plugins/restrict-elementor-widgets/assets/js/rew-admin.js/wp-content/plugins/restrict-elementor-widgets/assets/js/rew-frontend.js
Script Paths
/wp-content/plugins/restrict-elementor-widgets/assets/js/rew-admin.js/wp-content/plugins/restrict-elementor-widgets/assets/js/rew-frontend.js
Version Parameters
restrict-elementor-widgets/assets/css/rew-admin.css?ver=restrict-elementor-widgets/assets/css/rew-frontend.css?ver=restrict-elementor-widgets/assets/js/rew-admin.js?ver=restrict-elementor-widgets/assets/js/rew-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
elementor-control-rew_restrict_optionsrew-settings-notice-wrapper
HTML Comments
if accessed directly, exit.
Data Attributes
data-rew-controls
FAQ

Frequently Asked Questions about Restrict Elementor Widgets, Columns and Sections