Templementor – Persistent Elementor Templates Security & Risk Analysis

wordpress.org/plugins/templementor

Makes Elementor even greater by creating chainable templates to shape-up and manage entire website areas in minutes

40 active installs v1.0.2 PHP 7.0+ WP 5.0+ Updated Dec 11, 2024
elementorpage-builderpage-templatewordpress-builder
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Templementor – Persistent Elementor Templates Safe to Use in 2026?

Generally Safe

Score 92/100

Templementor – Persistent Elementor Templates has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of the "templementor" v1.0.2 plugin reveals a very limited attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events. This absence of direct entry points, especially unprotected ones, is a strong indicator of a generally secure design. The code also demonstrates good practices in handling SQL queries, exclusively using prepared statements, and includes at least one nonce check and capability check, which are essential for WordPress security.

However, a significant concern arises from the output escaping. With 5 total outputs and only 40% properly escaped, there's a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. This is the primary area of concern based on the static analysis. The taint analysis shows no flows, which is positive, but it's crucial to remember that taint analysis is not exhaustive and the lack of identified flows doesn't negate the risks identified by the output escaping metric.

The vulnerability history is entirely clean, with no recorded CVEs. This suggests that the plugin has either been very secure historically or has not been a target for widespread exploitation. While this is a positive sign, it should not be viewed as a guarantee of future security, especially given the identified potential for XSS.

In conclusion, "templementor" v1.0.2 presents a strong foundation with its minimal attack surface and secure database practices. The major weakness lies in the insufficient output escaping, which poses a tangible risk of XSS. The absence of past vulnerabilities is encouraging but should be considered in conjunction with the identified code-level risks.

Key Concerns

  • Insufficient output escaping (40% proper)
Vulnerabilities
None known

Templementor – Persistent Elementor Templates Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Templementor – Persistent Elementor Templates Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
2 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

40% escaped5 total outputs
Attack Surface

Templementor – Persistent Elementor Templates Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actionadmin_menuadmin_menu.php:6
actionparent_fileadmin_menu.php:22
actionsubmenu_fileadmin_menu.php:35
actiontemplate_redirectapply_template.php:2
filterbody_classapply_template.php:34
filterthe_contentapply_template.php:37
actionthe_contentapply_template.php:215
actionadmin_headmetabox.php:17
actionadmin_initmetabox.php:19
actionsave_postmetabox.php:73
actioninittemplates_pt.php:3
actioninittemplates_pt.php:44
actioninittemplementor.php:67
filterplugin_action_links_templementor/templementor.phptemplementor.php:85
filterplugin_row_metatemplementor.php:98
Maintenance & Trust

Templementor – Persistent Elementor Templates Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 11, 2024
PHP min version7.0
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

Templementor – Persistent Elementor Templates Developer Profile

LCweb

4 plugins · 90 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Templementor – Persistent Elementor Templates

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/templementor/css/style.css/wp-content/plugins/templementor/js/main.js
Script Paths
/wp-content/plugins/templementor/js/main.js
Version Parameters
templementor/style.css?ver=templementor/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
tpm_check_lcweb_pjcts_link
Data Attributes
tpm_template
Shortcode Output
{{contents}}{{title}}{{author}}{{pub-date}}
FAQ

Frequently Asked Questions about Templementor – Persistent Elementor Templates