Stratum Widgets for Elementor Security & Risk Analysis

wordpress.org/plugins/stratum

20+ Premium widgets for Elementor, including Advanced Slider, Instagram, Google Maps, Advanced Accordion, Post Grid.

30K active installs v1.6.2 PHP 5.6+ WP 5.0+ Updated Dec 19, 2025
elementorelementor-addonselementor-extraselementor-pluginselementor-widgets
95
A · Safe
CVEs total6
Unpatched0
Last CVEDec 27, 2025
Safety Verdict

Is Stratum Widgets for Elementor Safe to Use in 2026?

Generally Safe

Score 95/100

Stratum Widgets for Elementor has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

6 known CVEsLast CVE: Dec 27, 2025Updated 5mo ago
Risk Assessment

The plugin "stratum" v1.6.2 exhibits a mixed security posture. On the positive side, the static analysis reveals a commendable adherence to secure coding practices. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, a high percentage of output escaping, and the presence of nonce and capability checks all indicate a conscious effort to build a secure plugin. The limited attack surface and lack of observed taint flows are also encouraging signs.

However, the plugin's vulnerability history presents a significant concern. With 6 known medium severity CVEs, the pattern of "Missing Authorization," "Cross-site Scripting," and "Exposure of Sensitive Information" suggests recurring issues in fundamental security controls. Although there are currently no unpatched vulnerabilities, the past prevalence of these critical vulnerability types is a strong indicator of potential future risks. The plugin's strengths in static analysis are overshadowed by its historical track record, suggesting that despite improvements, underlying security weaknesses may persist or be introduced in new versions.

In conclusion, while "stratum" v1.6.2 demonstrates good static analysis results in terms of modern secure coding practices, its extensive history of medium-severity vulnerabilities, particularly those related to authorization and data handling, necessitates caution. Users should be aware of the past issues and ensure the plugin is consistently updated to the latest secure versions, as the historical pattern points to recurring security challenges.

Key Concerns

  • Multiple past medium severity CVEs
  • 3 external HTTP requests
  • 93% output escaping (potential for 7% unescaped)
Vulnerabilities
6 published

Stratum Widgets for Elementor Security Vulnerabilities

CVEs by Year

3 CVEs in 2024
2024
3 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
6

6 total CVEs

CVE-2025-69013medium · 4.3Missing Authorization

Stratum Widgets for Elementor <= 1.6.1 - Missing Authorization

Dec 27, 2025 Patched in 1.6.2 (11d)
CVE-2025-7845medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Stratum – Elementor Widgets <= 1.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Google Maps and Image Hotspot Widgets

Jul 31, 2025 Patched in 1.6.1 (1d)
CVE-2024-13642medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Stratum – Elementor Widgets <= 1.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting Vulnerability via Image Hotspot Widget

Jan 29, 2025 Patched in 1.5.0 (1d)
CVE-2024-10316medium · 4.3Exposure of Sensitive Information to an Unauthorized Actor

Stratum – Elementor Widgets <= 1.4.4 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates

Nov 20, 2024 Patched in 1.4.5 (1d)
CVE-2024-5611medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Stratum – Elementor Widgets <= 1.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

Jun 14, 2024 Patched in 1.4.2 (1d)
CVE-2024-29914medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Stratum <= 1.3.15 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 25, 2024 Patched in 1.3.16 (8d)
Version History

Stratum Widgets for Elementor Release Timeline

Code Analysis
Analyzed Mar 16, 2026

Stratum Widgets for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
66
865 escaped
Nonce Checks
3
Capability Checks
11
File Operations
0
External Requests
3
Bundled Libraries
1

Bundled Libraries

jQuery

Output Escaping

93% escaped931 total outputs
Attack Surface

Stratum Widgets for Elementor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 32
actionadmin_initincludes\admin-page.php:19
actionadmin_initincludes\admin-page.php:20
actionadmin_menuincludes\admin-page.php:21
actionadmin_enqueue_scriptsincludes\admin-page.php:22
actionadmin_noticesincludes\admin-page.php:112
actionadmin_noticesincludes\admin-page.php:116
actionelementor/ajax/register_actionsincludes\ajax-manager.php:18
filterexcerpt_lengthincludes\ajax-templates\advanced-posts.php:197
actionelementor/controls/registerincludes\controls-manager.php:25
actionadmin_menuincludes\premium.php:14
actionrest_api_initincludes\rest-api.php:19
actionelementor/initincludes\scripts-manager.php:36
actionelementor/editor/after_enqueue_stylesincludes\scripts-manager.php:39
actionelementor/editor/after_enqueue_stylesincludes\scripts-manager.php:40
actionelementor/editor/after_enqueue_stylesincludes\scripts-manager.php:41
actionelementor/editor/after_enqueue_stylesincludes\scripts-manager.php:42
actionelementor/frontend/before_register_scriptsincludes\scripts-manager.php:45
actionelementor/frontend/before_register_stylesincludes\scripts-manager.php:46
actionelementor/frontend/after_enqueue_stylesincludes\scripts-manager.php:47
actionelementor/frontend/after_enqueue_stylesincludes\scripts-manager.php:49
actionelementor/frontend/after_enqueue_scriptsincludes\scripts-manager.php:50
actionelementor/editor/after_saveincludes\scripts-manager.php:53
filterexcerpt_lengthincludes\templates\advanced-posts.php:305
actionstratum_refresh_instagram_tokenincludes\token-manager.php:14
filtercron_schedulesincludes\token-manager.php:15
actionupdate_optionincludes\token-manager.php:17
actionadmin_initincludes\token-manager.php:18
actionadmin_noticesincludes\token-manager.php:124
actioninitincludes\translation.php:12
actioninitincludes\version-control.php:39
actionelementor/widgets/registerincludes\widgets-manager.php:25
actionelementor/elements/categories_registeredincludes\widgets-manager.php:26

Scheduled Events 1

stratum_refresh_instagram_token
Maintenance & Trust

Stratum Widgets for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 19, 2025
PHP min version5.6
Downloads507K

Community Trust

Rating90/100
Number of ratings12
Active installs30K
Developer Profile

Stratum Widgets for Elementor Developer Profile

jetmonsters

33 plugins · 326K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
187 days
View full developer profile
Detection Fingerprints

How We Detect Stratum Widgets for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/stratum/assets/css/admin-page.min.css/wp-content/plugins/stratum/assets/css/stratum.min.css
Version Parameters
stratum/assets/css/admin-page.min.css?ver=stratum/assets/css/stratum.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
stratum-wrapstratum-headingstratum-logostratum-about-list
HTML Comments
<!-- start markdowntohtml.com -->
Data Attributes
data:image/svg+xml;base64,
FAQ

Frequently Asked Questions about Stratum Widgets for Elementor