Web Stories Widgets For Elementor Security & Risk Analysis

wordpress.org/plugins/shortcodes-for-amp-web-stories-and-elementor-widget

This addon will helps you to easily represent Google Web stories in the Page/Post using Elementor Widget and shortcodes.

1K active installs v1.2.6 PHP 5.6+ WP 5.0+ Updated Feb 23, 2026
amp-storieselementor-widgetsgoogleshortcodeweb-stories
99
A · Safe
CVEs total1
Unpatched0
Last CVENov 8, 2024
Safety Verdict

Is Web Stories Widgets For Elementor Safe to Use in 2026?

Generally Safe

Score 99/100

Web Stories Widgets For Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 8, 2024Updated 1mo ago
Risk Assessment

The plugin "shortcodes-for-amp-web-stories-and-elementor-widget" v1.2.6 exhibits a generally positive security posture with a strong adherence to secure coding practices. The analysis indicates robust use of prepared statements for SQL queries and a high percentage of properly escaped output, significantly mitigating common web vulnerabilities. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security profile. However, a notable concern arises from the presence of one unprotected AJAX handler, which represents a direct entry point that could be exploited if not properly secured against unauthorized access or malicious input. The vulnerability history, while showing no currently unpatched CVEs, does reveal a past medium-severity Cross-Site Scripting (XSS) vulnerability, suggesting that input sanitization and output escaping, while generally good, may require continued vigilance. The plugin's strengths lie in its proactive use of secure database and output handling, but the unprotected AJAX handler and past XSS vulnerability necessitate careful monitoring and potential remediation.

Key Concerns

  • Unprotected AJAX handler found
  • Past medium severity XSS vulnerability
Vulnerabilities
1

Web Stories Widgets For Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-52354medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Web Stories Widgets For Elementor <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 8, 2024 Patched in 1.1.1 (7d)
Code Analysis
Analyzed Mar 16, 2026

Web Stories Widgets For Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
112 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped117 total outputs
Attack Surface
1 unprotected

Web Stories Widgets For Elementor Attack Surface

Entry Points3
Unprotected1

AJAX Handlers 1

authwp_ajax_wsae_dismiss_noticeadmin\feedback\wsae-feedback-notice.php:20

Shortcodes 2

[webstory] Shortcodes For AMP Web Stories and Elementor Widget.php:74
[Recent-stories] Shortcodes For AMP Web Stories and Elementor Widget.php:75
WordPress Hooks 9
actionadmin_noticesadmin\feedback\wsae-feedback-notice.php:16
actionadmin_enqueue_scriptsadmin\feedback\wsae-feedback-notice.php:24
actionelementor/initincludes\class-WSAE.php:7
actionelementor/widgets/widgets_registeredincludes\class-WSAE.php:48
actionwp_enqueue_scriptsShortcodes For AMP Web Stories and Elementor Widget.php:70
actionplugins_loadedShortcodes For AMP Web Stories and Elementor Widget.php:73
filtermanage_web-story_posts_columnsShortcodes For AMP Web Stories and Elementor Widget.php:76
actionmanage_web-story_posts_custom_columnShortcodes For AMP Web Stories and Elementor Widget.php:77
actionadmin_noticesShortcodes For AMP Web Stories and Elementor Widget.php:261
Maintenance & Trust

Web Stories Widgets For Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 23, 2026
PHP min version5.6
Downloads18K

Community Trust

Rating100/100
Number of ratings6
Active installs1K
Developer Profile

Web Stories Widgets For Elementor Developer Profile

Cool Plugins

19 plugins · 109K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
490 days
View full developer profile
Detection Fingerprints

How We Detect Web Stories Widgets For Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shortcodes-for-amp-web-stories-and-elementor-widget/assets/js/amp-story-player-v0.js/wp-content/plugins/shortcodes-for-amp-web-stories-and-elementor-widget/assets/css/amp-story-player-v0.css/wp-content/plugins/shortcodes-for-amp-web-stories-and-elementor-widget/assets/css/wsae-custom-styl.css
Script Paths
/wp-content/plugins/shortcodes-for-amp-web-stories-and-elementor-widget/assets/js/amp-story-player-v0.js
Version Parameters
shortcodes-for-amp-web-stories-and-elementor-widget/assets/css/wsae-custom-styl.css?ver=amp-story-player-v0.js?ver=v0

HTML / DOM Fingerprints

Data Attributes
wsae-custom-styl.css
Shortcode Output
[webstory[Recent-stories
FAQ

Frequently Asked Questions about Web Stories Widgets For Elementor