
RTMKit Security & Risk Analysis
wordpress.org/plugins/rometheme-for-elementorAll-in-one toolkit for Elementor: advanced addons, theme builder, forms, icons & templates to build stunning sites fast and easy.
Is RTMKit Safe to Use in 2026?
Generally Safe
Score 89/100RTMKit has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin exhibits a mixed security posture. While it shows strengths in using prepared statements for SQL queries and a high percentage of properly escaped output, significant concerns arise from its attack surface and historical vulnerability patterns.
The static analysis reveals a considerable attack surface with 34 AJAX handlers, one of which lacks authentication checks. This unprotected entry point is a critical vulnerability that could allow unauthorized actions. Furthermore, six taint analysis flows with unsanitized paths indicate potential injection vulnerabilities, though the severity is not classified as critical or high in this specific analysis.
The plugin's vulnerability history is deeply concerning, with a total of 12 known CVEs, including 2 high and 10 medium severity vulnerabilities. The types of past vulnerabilities, such as Unrestricted Upload, Cross-Site Scripting, Authorization Bypass, Missing Authorization, and Information Exposure, suggest a recurring pattern of insecure coding practices related to input validation, authorization, and secure handling of user-provided data. The fact that there are currently no unpatched CVEs is positive, but the sheer volume and nature of past issues indicate a systemic risk that demands careful attention. The last vulnerability date is in the future, which is unusual but not directly relevant to the current risk assessment.
Key Concerns
- AJAX handler without authentication check
- Flows with unsanitized paths identified
- High number of past high severity CVEs
- High number of past medium severity CVEs
- Recurring vulnerability types: Unrestricted Upload, XSS, Auth Bypass, Info Expos
RTMKit Security Vulnerabilities
CVEs by Year
Severity Breakdown
12 total CVEs
RTMKit <= 1.6.8 - Reflected Cross-Site Scripting via 'themebuilder' Parameter
RTMKit Addons <= 1.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Repeater Block Attribute
RTMKit <= 1.6.5 - Authenticated (Contributor+) Arbitrary File Upload
RTMKit Addons for Elementor <= 1.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
RomethemeKit For Elementor <= 1.5.4 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation
RTMKit <= 1.6.7 - Authenticated (Contributor+) Insecure Direct Object Reference
RomethemeKit For Elementor <= 1.5.2 - Missing Authorization
RomethemeKit For Elementor <= 1.5.2 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates
RomethemeKit For Elementor <= 1.5.3 - Missing Authorization in save_options and reset_widgets
RomethemeKit For Elementor <= 1.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
RomethemeKit For Elementor <= 1.4.1 - Missing Authorization
RomethemeKit For Elementor <= 1.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
RTMKit Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
RTMKit Attack Surface
AJAX Handlers 34
WordPress Hooks 69
Maintenance & Trust
RTMKit Maintenance & Trust
Maintenance Signals
Community Trust
RTMKit Alternatives
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Turbo Addons Elementor
turbo-addons-elementor
Turbo Addons for Elementor offers advanced widgets to enhance Elementor, helping you create professional, interactive websites easily and quickly.
Essential Classy Addons – Widgets & Templates for Elementor
essential-classy-addons-for-elementor
Post Grid, Woocommerce builder Widgets. Slider, Carousel, Testimonial.A lightweight collection of ready-to-use widgets, templates, and extensions.
Selleradise Elements – Elementor Addons
selleradise-widgets
Selleradise Elements adds powerful Elementor widgets and WooCommerce integrations for beautiful, conversion-focused sites.
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
premium-addons-for-elementor
Elementor Carousel, Mega Menu, Posts List/Slider, Media Gallery, WooCommerce Widgets, Display Conditions, Premade Templates & more.
RTMKit Developer Profile
2 plugins · 80K total installs
How We Detect RTMKit
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rometheme-for-elementor/assets/css/rtmkit.css/wp-content/plugins/rometheme-for-elementor/assets/js/rtmkit.js/wp-content/plugins/rometheme-for-elementor/assets/css/rtmkit-icons.css/wp-content/plugins/rometheme-for-elementor/assets/js/rtmkit.jsrometheme-for-elementor/assets/css/rtmkit.css?ver=rometheme-for-elementor/assets/js/rtmkit.js?ver=rometheme-for-elementor/assets/css/rtmkit-icons.css?ver=HTML / DOM Fingerprints
rtmkit-addonrtmkit-modulertmkit-setup-wizarddata-rtmkit-idRTMKit