SKT Addons for Elementor Security & Risk Analysis

wordpress.org/plugins/skt-addons-for-elementor

SKT Addons for Elementor is one of the great Elementor Addons which comes With 123 completely Free Elementor Widgets including Business hour, image gr …

1K active installs v3.9 PHP 7.4+ WP 5.0+ Updated Aug 20, 2025
elementorelementor-addonselementor-extensionelementor-widgetpage-builder
94
A · Safe
CVEs total7
Unpatched0
Last CVESep 5, 2025
Safety Verdict

Is SKT Addons for Elementor Safe to Use in 2026?

Generally Safe

Score 94/100

SKT Addons for Elementor has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

7 known CVEsLast CVE: Sep 5, 2025Updated 8mo ago
Risk Assessment

The static analysis of skt-addons-for-elementor v3.9 reveals generally good security practices, with a strong emphasis on prepared statements for SQL queries and proper output escaping. The plugin also demonstrates a commendable number of nonce and capability checks, indicating a conscious effort to protect its entry points. However, the presence of unsanitized paths in two TAINT analysis flows, even without critical or high severity, warrants attention as these could potentially lead to vulnerabilities if exploited. The file operation and external HTTP requests, while not explicitly flagged as problematic in the static analysis, represent potential vectors for attack if not handled with extreme care.

The vulnerability history for this plugin is a significant concern. With a total of 7 known CVEs, including one high-severity and six medium-severity vulnerabilities, it suggests a recurring pattern of security weaknesses. The common vulnerability types, Authorization Bypass and Cross-site Scripting, are particularly serious and can have a substantial impact. Although there are currently no unpatched vulnerabilities, the historical prevalence of these issues, especially the recent one in 2025, suggests that future vulnerabilities are likely if the development team does not address the underlying causes of these past exploits. The plugin has a good number of protected entry points, but the historical track record indicates a need for more robust security auditing and potentially a more rigorous development lifecycle.

Overall, skt-addons-for-elementor v3.9 exhibits some strong security fundamentals in its code, but its past vulnerability record casts a significant shadow. The plugin's reliance on external libraries also presents a potential risk if those libraries are not kept up-to-date. While the immediate static analysis shows minimal critical flaws, the historical data points to a history of security issues that require proactive attention from the developers to ensure long-term security.

Key Concerns

  • Taint flows with unsanitized paths
  • 1 high severity CVE historically
  • 6 medium severity CVEs historically
  • Bundled libraries (potential outdatedness)
  • File operation detected
  • External HTTP requests detected
Vulnerabilities
7 published

SKT Addons for Elementor Security Vulnerabilities

CVEs by Year

5 CVEs in 2024
2024
2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
6

7 total CVEs

CVE-2025-8564medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SKT Addons for Elementor <= 3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

Sep 5, 2025 Patched in 3.8 (1d)
CVE-2025-30812medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SKT Addons for Elementor <= 3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 27, 2025 Patched in 3.6 (7d)
CVE-2024-10693medium · 4.3Authorization Bypass Through User-Controlled Key

SKT Addons for Elementor <= 3.3 - Authenticated (Contributor+) Post Disclosure

Nov 8, 2024 Patched in 3.4 (1d)
CVE-2024-38674medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SKT Addons for Elementor <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jul 10, 2024 Patched in 3.2 (90d)
CVE-2024-5091high · 7.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SKT Addons for Elementor <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate and Creative Slider Widgets

Jun 7, 2024 Patched in 2.1 (1d)
CVE-2024-34445medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SKT Addons for Elementor <= 1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Page Title

May 7, 2024 Patched in 1.9 (10d)
CVE-2024-34436medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SKT Addons for Elementor <= 1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Block

May 7, 2024 Patched in 1.9 (10d)
Version History

SKT Addons for Elementor Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

SKT Addons for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
9 prepared
Unescaped Output
72
1998 escaped
Nonce Checks
21
Capability Checks
27
File Operations
1
External Requests
4
Bundled Libraries
2

Bundled Libraries

DataTablesSelect2

SQL Query Safety

82% prepared11 total queries

Output Escaping

97% escaped2070 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

6 flows2 with unsanitized paths
insert_subscriber_to_mailchimp (widgets\mailchimp\mailchimp-api.php:25)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SKT Addons for Elementor Attack Surface

Entry Points14
Unprotected0

AJAX Handlers 14

authwp_ajax_skt_addons_elementor_clear_cacheclasses\admin-bar.php:12
authwp_ajax_skt_addons_elementor_smart_post_list_actionclasses\ajax-handler.php:26
noprivwp_ajax_skt_addons_elementor_smart_post_list_actionclasses\ajax-handler.php:27
authwp_ajax_sktaddonselementorextra_post_grid_ajaxclasses\ajax-handler.php:29
noprivwp_ajax_sktaddonselementorextra_post_grid_ajaxclasses\ajax-handler.php:30
authwp_ajax_skt_addons_elementor_post_tab_actionclasses\ajax-handler.php:32
noprivwp_ajax_skt_addons_elementor_post_tab_actionclasses\ajax-handler.php:33
authwp_ajax_skt_addons_elementor_mailchimp_ajaxclasses\ajax-handler.php:35
noprivwp_ajax_skt_addons_elementor_mailchimp_ajaxclasses\ajax-handler.php:36
authwp_ajax_skt_show_edd_product_quick_viewclasses\ajax-handler.php:38
noprivwp_ajax_skt_show_edd_product_quick_viewclasses\ajax-handler.php:39
authwp_ajax_skt_edd_ajax_add_to_cart_linkclasses\ajax-handler.php:41
noprivwp_ajax_skt_edd_ajax_add_to_cart_linkclasses\ajax-handler.php:42
authwp_ajax_skt_addons_elementor_process_dynamic_selectclasses\select2-handler.php:11
WordPress Hooks 98
actioninitbase.php:29
actionelementor/elements/categories_registeredbase.php:44
actionelementor/controls/controls_registeredbase.php:47
actioninitbase.php:49
actionadmin_bar_menuclasses\admin-bar.php:9
actionwp_enqueue_scriptsclasses\admin-bar.php:10
actionadmin_enqueue_scriptsclasses\admin-bar.php:11
filteredd_purchase_link_defaultsclasses\ajax-handler.php:283
actionwp_enqueue_scriptsclasses\assets-manager.php:17
actionwp_enqueue_scriptsclasses\assets-manager.php:18
actionelementor/css-file/post/enqueueclasses\assets-manager.php:19
actionelementor/preview/enqueue_stylesclasses\assets-manager.php:22
actionelementor/editor/after_enqueue_scriptsclasses\assets-manager.php:25
filterelementor/editor/localize_settingsclasses\assets-manager.php:28
actionelementor/editor/after_saveclasses\cache-manager.php:13
actionafter_delete_postclasses\cache-manager.php:14
filterpost_row_actionsclasses\clone-handler.php:21
filterpage_row_actionsclasses\clone-handler.php:22
actionadmin_menuclasses\dashboard.php:26
actionadmin_menuclasses\dashboard.php:27
actionadmin_enqueue_scriptsclasses\dashboard.php:28
actionsktaddonselementor_save_dashboard_dataclasses\dashboard.php:33
actionsktaddonselementor_save_dashboard_dataclasses\dashboard.php:34
actionsktaddonselementor_save_dashboard_dataclasses\dashboard.php:35
actionsktaddonselementor_save_dashboard_dataclasses\dashboard.php:36
actionin_admin_headerclasses\dashboard.php:38
filterelementor/icons_manager/additional_tabsclasses\icons-manager.php:9
filterposts_whereclasses\template-query-manager.php:123
actionelementor/widgets/widgets_registeredclasses\widgets-manager.php:19
actionelementor/frontend/before_renderclasses\widgets-manager.php:20
filterwpml_elementor_widgets_to_translateclasses\wpml-manager.php:12
actionwpml_translation_job_savedclasses\wpml-manager.php:13
actionelementor/element/common/_section_style/after_section_endextensions\advanced-tooltip.php:18
actionelementor/frontend/widget/before_renderextensions\advanced-tooltip.php:20
actionelementor/preview/enqueue_scriptsextensions\advanced-tooltip.php:22
actionelementor/element/common/_section_background/after_section_endextensions\background-overlay.php:14
actionelementor/element/after_add_attributesextensions\background-overlay.php:15
actionelementor/element/column/layout/before_section_endextensions\column-extended.php:17
actionelementor/element/common/_section_style/after_section_endextensions\css-transform.php:17
filterelementor/frontend/section/should_renderextensions\display-conditions.php:87
filterelementor/frontend/column/should_renderextensions\display-conditions.php:88
filterelementor/frontend/widget/should_renderextensions\display-conditions.php:89
actionelementor/element/common/_section_style/after_section_endextensions\floating-effects.php:19
actionelementor/frontend/widget/before_renderextensions\floating-effects.php:21
actionelementor/preview/enqueue_scriptsextensions\floating-effects.php:23
actionelementor/documents/register_controlsextensions\grid-layer.php:11
actionelementor/element/image/section_image/before_section_endextensions\image-masking.php:17
actionelementor/element/image-box/section_image/before_section_endextensions\image-masking.php:18
actionelementor/element/skt-card/_section_image/before_section_endextensions\image-masking.php:19
actionelementor/element/skt-infobox/_section_media/before_section_endextensions\image-masking.php:20
actionelementor/element/skt-promo-box/_section_title/before_section_endextensions\image-masking.php:21
actionelementor/element/skt-member/_section_info/before_section_endextensions\image-masking.php:22
filterelementor/shapes/additional_shapesextensions\shape-divider.php:13
actionelementor/element/section/section_shape_divider/before_section_endextensions\shape-divider.php:14
actionelementor/element/common/_section_style/after_section_endextensions\skt-features.php:13
actionelementor/element/column/section_advanced/after_section_endextensions\skt-features.php:15
actionelementor/element/section/section_advanced/after_section_endextensions\skt-features.php:17
actionelementor/element/after_section_endextensions\skt-particle-effects.php:23
actionelementor/preview/enqueue_scriptsextensions\skt-particle-effects.php:25
actionelementor/column/print_templateextensions\skt-particle-effects.php:27
actionelementor/section/print_templateextensions\skt-particle-effects.php:28
actionelementor/frontend/column/before_renderextensions\skt-particle-effects.php:30
actionelementor/frontend/section/before_renderextensions\skt-particle-effects.php:31
actionelementor/frontend/column/before_renderextensions\skt-particle-effects.php:33
actionelementor/frontend/section/before_renderextensions\skt-particle-effects.php:34
actionelementor/element/button/section_style/after_section_startextensions\widgets-extended.php:18
actionelementor/element/heading/section_title_style/after_section_endextensions\widgets-extended.php:21
actionelementor/element/theme-page-title/section_title_style/after_section_endextensions\widgets-extended.php:22
actionelementor/element/theme-site-title/section_title_style/after_section_endextensions\widgets-extended.php:23
actionelementor/element/theme-post-title/section_title_style/after_section_endextensions\widgets-extended.php:24
actionelementor/element/woocommerce-product-title/section_title_style/after_section_endextensions\widgets-extended.php:25
actionelementor/element/animated-headline/section_style_text/after_section_endextensions\widgets-extended.php:26
actionelementor/element/skt-gradient-heading/_section_style_title/after_section_endextensions\widgets-extended.php:27
actionelementor/element/column/section_advanced/after_section_endextensions\wrapper-link.php:12
actionelementor/element/section/section_advanced/after_section_endextensions\wrapper-link.php:13
actionelementor/element/common/_section_style/after_section_endextensions\wrapper-link.php:14
actionelementor/frontend/before_renderextensions\wrapper-link.php:16
filterwoocommerce_add_to_cart_fragmentsinc\functions.php:730
actionadmin_noticesplugin.php:44
actionadmin_noticesplugin.php:50
actionadmin_noticesplugin.php:56
actionplugins_loadedplugin.php:64
actionedd_checkout_form_topwidgets\edd-checkout\widget.php:1980
filteredd_login_formwidgets\edd-login\widget.php:724
filteredd_purchase_link_defaultswidgets\edd-product-carousel\widget.php:2142
filteredd_purchase_link_defaultswidgets\edd-product-grid\widget.php:2323
filteredd_purchase_download_formwidgets\edd-product-grid\widget.php:2324
filteredd_register_formwidgets\edd-register\widget.php:647
filteredd_purchase_link_defaultswidgets\edd-single-product\widget.php:2425
filterwoocommerce_product_add_to_cart_textwidgets\product-carousel-new\widget.php:1435
filtersingle_product_archive_thumbnail_sizewidgets\product-grid-new\widget.php:1449
filterwoocommerce_product_add_to_cart_textwidgets\product-grid-new\widget.php:1450
filterwoocommerce_loop_add_to_cart_linkwidgets\product-grid-new\widget.php:1452
filtersingle_product_archive_thumbnail_sizewidgets\single-product-new\widget.php:1834
filterwoocommerce_product_add_to_cart_textwidgets\single-product-new\widget.php:1835
filterwoocommerce_loop_add_to_cart_linkwidgets\single-product-new\widget.php:1837
filterwoocommerce_coupons_enabledwidgets\wc-cart\widget.php:1811
actionwoocommerce_cart_collateralswidgets\wc-cart\widget.php:1816
Maintenance & Trust

SKT Addons for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 20, 2025
PHP min version7.4
Downloads21K

Community Trust

Rating94/100
Number of ratings3
Active installs1K
Developer Profile

SKT Addons for Elementor Developer Profile

sonalsinha21

153 plugins · 54K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
60 days
View full developer profile
Detection Fingerprints

How We Detect SKT Addons for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/skt-addons-for-elementor/assets/admin/css/admin.min.css/wp-content/plugins/skt-addons-for-elementor/assets/admin/js/admin.min.js
Script Paths
/wp-content/plugins/skt-addons-for-elementor/assets/admin/js/admin.min.js
Version Parameters
skt-addons-for-elementor/assets/admin/css/admin.min.css?ver=skt-addons-for-elementor/assets/admin/js/admin.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
skt-addons-for-elementor-admin
JS Globals
SktAdmin
FAQ

Frequently Asked Questions about SKT Addons for Elementor