RLM Elementor Widgets Pack Security & Risk Analysis

wordpress.org/plugins/rlm-elementor-widgets-pack

Custom Elementor widgets for restaurant menus, hours, locations, ordering, headers, specials, and calls to action.

10 active installs v1.6.5 PHP 7.4+ WP 5.0+ Updated Mar 31, 2026
elementorhoursmenurestaurantwidgets
99
A · Safe
CVEs total1
Unpatched0
Last CVEOct 31, 2024
Download
Safety Verdict

Is RLM Elementor Widgets Pack Safe to Use in 2026?

Generally Safe

Score 99/100

RLM Elementor Widgets Pack has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 31, 2024Updated 5d ago
Risk Assessment

The static analysis of rlm-elementor-widgets-pack v1.6.2 reveals a generally strong security posture. The plugin exhibits excellent practices by having no detected dangerous functions, all SQL queries utilizing prepared statements, and a high percentage of properly escaped output. Furthermore, there are no file operations, external HTTP requests, or indications of bundled libraries, which minimizes common attack vectors.

However, a significant concern arises from the complete absence of nonce checks and capability checks across all entry points. While the attack surface appears to be zero in terms of AJAX handlers, REST API routes, shortcodes, and cron events, this is likely due to the plugin not exposing any such functionalities in this version. The lack of these fundamental security measures on any potential future entry points or if this version is a minimal representation is a notable weakness.

The vulnerability history indicates one past medium-severity CVE, specifically Cross-site Scripting, which was patched. The fact that there are no currently unpatched vulnerabilities is positive, but the historical presence of a XSS vulnerability, even if medium, warrants attention. In conclusion, while the current code demonstrates good practices in preventing common vulnerabilities, the lack of critical security mechanisms like nonce and capability checks presents a potential risk if the attack surface were to expand or if this analysis doesn't capture all potential interaction points.

Key Concerns

  • No nonce checks
  • No capability checks
  • 1 medium CVE in history
  • 11% of output not properly escaped
Vulnerabilities
1

RLM Elementor Widgets Pack Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-50542medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

RLM Elementor Widgets Pack <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Oct 31, 2024 Patched in 1.4.0 (7d)
Version History

RLM Elementor Widgets Pack Release Timeline

v1.6.5Current
v1.6.4
v1.6.3
v1.6.2
v1.6.1
v1.4.0
v1.3.11 CVE
v1.3.01 CVE
Code Analysis
Analyzed Mar 17, 2026

RLM Elementor Widgets Pack Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
22
172 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

89% escaped194 total outputs
Attack Surface

RLM Elementor Widgets Pack Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionelementor/widgets/registerelementor-addon.php:46
actionelementor/frontend/after_register_styleselementor-addon.php:93
actionelementor/frontend/after_register_scriptselementor-addon.php:134
actionelementor/elements/categories_registeredelementor-addon.php:152
Maintenance & Trust

RLM Elementor Widgets Pack Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 31, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

RLM Elementor Widgets Pack Developer Profile

zachsilberstein

1 plugin · 10 total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect RLM Elementor Widgets Pack

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rlm-elementor-widgets-pack/assets/css/food-menu.css/wp-content/plugins/rlm-elementor-widgets-pack/assets/css/marquee-banner.css/wp-content/plugins/rlm-elementor-widgets-pack/assets/css/hours-open-now.css/wp-content/plugins/rlm-elementor-widgets-pack/assets/css/order-online-hub.css/wp-content/plugins/rlm-elementor-widgets-pack/assets/css/multi-location.css/wp-content/plugins/rlm-elementor-widgets-pack/assets/js/food-menu.js/wp-content/plugins/rlm-elementor-widgets-pack/assets/js/hours-open-now.js/wp-content/plugins/rlm-elementor-widgets-pack/assets/js/order-online-hub.js+1 more
Version Parameters
rlm-elementor-widgets-pack/assets/css/food-menu.css?ver=1.6.2rlm-elementor-widgets-pack/assets/css/marquee-banner.css?ver=1.6.2rlm-elementor-widgets-pack/assets/css/hours-open-now.css?ver=1.6.2rlm-elementor-widgets-pack/assets/css/order-online-hub.css?ver=1.6.2rlm-elementor-widgets-pack/assets/css/multi-location.css?ver=1.6.2rlm-elementor-widgets-pack/assets/js/food-menu.js?ver=1.6.2rlm-elementor-widgets-pack/assets/js/hours-open-now.js?ver=1.6.2rlm-elementor-widgets-pack/assets/js/order-online-hub.js?ver=1.6.2rlm-elementor-widgets-pack/assets/js/multi-location.js?ver=1.6.2

HTML / DOM Fingerprints

CSS Classes
rlm-widgetrlm-food-menu-widgetrlm-marquee-banner-widgetrlm-hours-open-now-widgetrlm-order-online-hub-widgetrlm-multi-location-widget
Data Attributes
data-rlm-widget-id
JS Globals
rlm_food_menu_widgetrlm_hours_open_now_widgetrlm_order_online_hub_widgetrlm_multi_location_widget
FAQ

Frequently Asked Questions about RLM Elementor Widgets Pack