ShopElement – Elementor Addons for WooCommerce Product Grid, Carousel & Category Widgets Security & Risk Analysis

wordpress.org/plugins/shopelement

Build beautiful WooCommerce stores with powerful Elementor widgets - product grids, carousels, categories, banners, reviews, and more.

90 active installs v2.1.3 PHP 7.0+ WP 5.0+ Updated Feb 19, 2026
elementorproductproduct-carouselproduct-gridwoocommerce
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 30, 2024
Safety Verdict

Is ShopElement – Elementor Addons for WooCommerce Product Grid, Carousel & Category Widgets Safe to Use in 2026?

Generally Safe

Score 99/100

ShopElement – Elementor Addons for WooCommerce Product Grid, Carousel & Category Widgets has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Dec 30, 2024Updated 2mo ago
Risk Assessment

The static analysis of "shopelement" v2.1.3 indicates a generally strong security posture in terms of common web vulnerabilities. The plugin exhibits excellent practices with 100% of SQL queries using prepared statements and all output being properly escaped, which significantly mitigates risks of SQL injection and Cross-Site Scripting (XSS) from direct output manipulation. The absence of dangerous functions and external HTTP requests further strengthens its defensibility. However, a critical concern arises from the complete lack of nonce checks and capability checks across all entry points, including potential AJAX handlers and REST API routes if they existed (though the analysis reports zero). This suggests that even if the current version has no exposed entry points, any future addition or modification could introduce severe vulnerabilities if not properly secured with authorization mechanisms. The vulnerability history reveals a single medium-severity CVE related to XSS, with the last recorded vulnerability being recent. While this CVE is currently unpatched, the fact that there's only one and it's of medium severity suggests that the developer has been responsive to security issues, but the existence of a prior XSS vulnerability, even if fixed, warrants ongoing vigilance.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • Past medium severity CVE (XSS)
Vulnerabilities
1 published

ShopElement – Elementor Addons for WooCommerce Product Grid, Carousel & Category Widgets Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-56260medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

ShopElement <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 30, 2024 Patched in 2.1.0 (10d)
Version History

ShopElement – Elementor Addons for WooCommerce Product Grid, Carousel & Category Widgets Release Timeline

v2.1.3Current
v2.1.2
v2.1.1
v2.1.0
v2.0.01 CVE
v1.0.01 CVE
Code Analysis
Analyzed Apr 16, 2026

ShopElement – Elementor Addons for WooCommerce Product Grid, Carousel & Category Widgets Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
801 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped801 total outputs
Attack Surface

ShopElement – Elementor Addons for WooCommerce Product Grid, Carousel & Category Widgets Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionelementor/widgets/registerincludes/Abstracts/Autowire.php:133
actionwp_enqueue_scriptsincludes/Assets.php:26
actionadmin_enqueue_scriptsincludes/Assets.php:27
actionelementor/frontend/before_register_scriptsincludes/Assets.php:28
actionelementor/editor/before_register_scriptsincludes/Assets.php:29
actionelementor/editor/after_enqueue_scriptsincludes/Assets.php:30
actionelementor/frontend/after_enqueue_stylesincludes/Assets.php:31
actionelementor/editor/after_enqueue_stylesincludes/Assets.php:32
actionadmin_noticesincludes/Singleton.php:98
actionadmin_noticesincludes/Singleton.php:104
actionadmin_noticesincludes/Singleton.php:110
actionadmin_noticesincludes/Singleton.php:116
actionelementor/elements/categories_registeredincludes/WidgetCategory.php:15
actionplugins_loadedshopelement.php:62
Maintenance & Trust

ShopElement – Elementor Addons for WooCommerce Product Grid, Carousel & Category Widgets Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 19, 2026
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs90
Developer Profile

ShopElement – Elementor Addons for WooCommerce Product Grid, Carousel & Category Widgets Developer Profile

StorePlugin

7 plugins · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
10 days
View full developer profile
Detection Fingerprints

How We Detect ShopElement – Elementor Addons for WooCommerce Product Grid, Carousel & Category Widgets

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shopelement/assets/css/shopelement.css/wp-content/plugins/shopelement/assets/css/slick.css/wp-content/plugins/shopelement/assets/css/icondivi.css/wp-content/plugins/shopelement/assets/css/product-grid-carousel.css/wp-content/plugins/shopelement/assets/css/product-grid.css/wp-content/plugins/shopelement/assets/css/product-list.css/wp-content/plugins/shopelement/assets/css/product-carousel.css/wp-content/plugins/shopelement/assets/css/product-category.css+15 more
Script Paths
/wp-content/plugins/shopelement/assets/js/swiper-bundle.min.js/wp-content/plugins/shopelement/assets/js/slick.min.js/wp-content/plugins/shopelement/assets/js/customer-review-carousel.js/wp-content/plugins/shopelement/assets/js/testing-editor.js/wp-content/plugins/shopelement/assets/js/main.js/wp-content/plugins/shopelement/assets/js/elementor-editor.js
Version Parameters
shopelement/assets/css/shopelement.css?ver=shopelement/assets/css/slick.css?ver=shopelement/assets/css/icondivi.css?ver=shopelement/assets/css/product-grid-carousel.css?ver=shopelement/assets/css/product-grid.css?ver=shopelement/assets/css/product-list.css?ver=shopelement/assets/css/product-carousel.css?ver=shopelement/assets/css/product-category.css?ver=shopelement/assets/css/logo.css?ver=shopelement/assets/css/product-banner.css?ver=shopelement/assets/css/store-feature.css?ver=shopelement/assets/css/product-review.css?ver=shopelement/assets/css/customer-review-carousel.css?ver=shopelement/assets/css/customer-review.css?ver=shopelement/assets/css/customer-reviewcarousel.css?ver=shopelement/assets/css/main.css?ver=shopelement/assets/js/swiper-bundle.min.js?ver=shopelement/assets/js/slick.min.js?ver=shopelement/assets/js/customer-review-carousel.js?ver=shopelement/assets/js/testing-editor.js?ver=shopelement/assets/js/main.js?ver=shopelement/assets/js/elementor-editor.js?ver=shopelement/assets/css/elementor-editor.css?ver=

HTML / DOM Fingerprints

CSS Classes
shopelement-product-category
Data Attributes
data-widget_type="shopelement-product-category"
JS Globals
SHOPELEMENT_ACT
FAQ

Frequently Asked Questions about ShopElement – Elementor Addons for WooCommerce Product Grid, Carousel & Category Widgets