Tweaks for Elementor Security & Risk Analysis

wordpress.org/plugins/tweaks-for-elementor

Tweaks for Elementor

400 active installs v1.0.6 PHP 5.6.20+ WP 5.7+ Updated May 30, 2022
designelementoroptimizationseospeed
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tweaks for Elementor Safe to Use in 2026?

Generally Safe

Score 85/100

Tweaks for Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin 'tweaks-for-elementor' v1.0.6 exhibits a strong security posture based on the provided static analysis. There are no identified entry points such as AJAX handlers, REST API routes, or shortcodes that are exposed without proper authentication or permission checks. The code signals also indicate good practices, with no dangerous functions used, all SQL queries employing prepared statements, and no file operations or external HTTP requests. The absence of vulnerability history further contributes to a positive assessment.

However, there are minor areas for concern. The output escaping is only 50% properly implemented, meaning some output may not be sufficiently sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly reflected in the output. Furthermore, the lack of explicit nonce checks and capability checks, while not directly identified as a vulnerability due to the limited attack surface, could become a risk if new functionalities are added without adhering to these security best practices. The taint analysis results are neutral due to the lack of observable flows, but this is likely a reflection of the limited attack surface rather than a guarantee of absolute safety.

In conclusion, the plugin appears to be developed with security in mind, particularly in its handling of common web vulnerabilities. The primary weakness lies in the partial output escaping, which warrants attention. The overall security is good, but the potential for XSS due to incomplete output sanitization is a notable weakness. The absence of historical vulnerabilities is a positive indicator, suggesting consistent security practices.

Key Concerns

  • 50% of output not properly escaped
Vulnerabilities
None known

Tweaks for Elementor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Tweaks for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped2 total outputs
Attack Surface

Tweaks for Elementor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
filterplugin_row_metaincludes\class-admin.php:24
actionin_admin_headerincludes\class-admin.php:26
actionwp_enqueue_scriptsincludes\class-main.php:44
actionwp_print_stylesincludes\class-main.php:45
actionplugins_loadedincludes\class-main.php:46
actionelementor/frontend/after_register_stylesincludes\class-main.php:47
filterelementor/frontend/print_google_fontsincludes\class-main.php:80
filterhello_elementor_enqueue_styleincludes\class-main.php:89
filterhello_elementor_enqueue_theme_styleincludes\class-main.php:90
filterpre_wp_mailincludes\class-main.php:99
actionelementor/admin/after_create_settings/elementorincludes\class-options.php:30
actionadmin_noticestweaks-for-elementor.php:45
actionplugins_loadedtweaks-for-elementor.php:59
Maintenance & Trust

Tweaks for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedMay 30, 2022
PHP min version5.6.20
Downloads4K

Community Trust

Rating100/100
Number of ratings5
Active installs400
Developer Profile

Tweaks for Elementor Developer Profile

Dima Minka

1 plugin · 400 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tweaks for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tweaks-for-elementor/dist/style.css/wp-content/plugins/tweaks-for-elementor/dist/script.js
Script Paths
/wp-content/plugins/tweaks-for-elementor/dist/script.js
Version Parameters
tweaks-for-elementor/dist/style.css?ver=tweaks-for-elementor/dist/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
elementor-field-group-
JS Globals
intlElementorData
FAQ

Frequently Asked Questions about Tweaks for Elementor