Flipbox Addon for Elementor Security & Risk Analysis

wordpress.org/plugins/ultimate-flipbox-addon-for-elementor

Flip Boxes for Elementor – animated, 3D, responsive flip box widgets for posts, custom post types, portfolios, and product showcases.

300 active installs v2.0.8 PHP 7.0+ WP 5.0+ Updated Mar 4, 2026
elementor-flipboxflip-boxflip-box-widgetflip-boxesflipbox
99
A · Safe
CVEs total1
Unpatched0
Last CVENov 8, 2024
Safety Verdict

Is Flipbox Addon for Elementor Safe to Use in 2026?

Generally Safe

Score 99/100

Flipbox Addon for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 8, 2024Updated 1mo ago
Risk Assessment

The ultimate-flipbox-addon-for-elementor plugin v2.0.8 exhibits a generally strong security posture, with a low number of entry points and robust implementation of security best practices. The static analysis shows no dangerous functions, all SQL queries are prepared, and a very high percentage of output is properly escaped. Nonce and capability checks are present on all identified AJAX handlers, and there are no unhandled taint flows or unsanitized paths. This indicates a proactive approach to secure coding and input validation within the plugin's codebase.

However, the plugin does make two external HTTP requests, which can be a potential vector for vulnerabilities if the remote endpoints are compromised or if the requests are not handled securely. While the vulnerability history shows only one medium-severity CVE in the past, its recency (November 2024) and the common vulnerability type of Cross-Site Scripting (XSS) warrant continued vigilance. The fact that this CVE is currently patched is positive, but it highlights the potential for XSS to be introduced in this type of plugin.

In conclusion, the plugin is well-developed from a security perspective, demonstrating good practices in critical areas like SQL and output escaping. The primary areas for attention are the external HTTP requests and the awareness of past XSS vulnerabilities, which, while patched, suggest a type of vulnerability that can be easily introduced if input handling isn't meticulously maintained.

Key Concerns

  • External HTTP requests present
  • Past medium severity CVE (XSS)
Vulnerabilities
1

Flipbox Addon for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-51870medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Ultimate Flipbox Addon for Elementor 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 8, 2024 Patched in 1.0.5 (46d)
Code Analysis
Analyzed Mar 16, 2026

Flipbox Addon for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
368 escaped
Nonce Checks
3
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

97% escaped378 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
ufae_preset_styles (includes\class-ufae-ajax-handler.php:52)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Flipbox Addon for Elementor Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_ufae_send_feedbackadmin\feedback\class-ufae-feedback-form.php:76
authwp_ajax_ufae_review_dismissadmin\review\class-ufae-review-form.php:40
authwp_ajax_ufae_preset_stylesincludes\class-ufae-ajax-handler.php:43
WordPress Hooks 13
actionadmin_enqueue_scriptsadmin\feedback\class-ufae-feedback-form.php:77
actionadmin_headadmin\feedback\class-ufae-feedback-form.php:78
actionadmin_noticesadmin\review\class-ufae-review-form.php:38
actionadmin_enqueue_scriptsadmin\review\class-ufae-review-form.php:39
actionelementor/widgets/registerincludes\class-ufae-register.php:48
actionelementor/initincludes\class-ufae-register.php:49
actionelementor/controls/registerincludes\class-ufae-register.php:50
actionplugins_loadedultimate-flipbox-addon-for-elementor.php:79
actionadmin_initultimate-flipbox-addon-for-elementor.php:80
actionadmin_noticesultimate-flipbox-addon-for-elementor.php:175
actionelementor/frontend/after_enqueue_scriptswidget\post\class-ufae-post-widget.php:41
actionelementor/frontend/after_enqueue_scriptswidget\simple\class-ufae-simple-widget.php:48
actionelementor/frontend/after_enqueue_scriptswidget\stories\class-ufae-stories-widget.php:50
Maintenance & Trust

Flipbox Addon for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 4, 2026
PHP min version7.0
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs300
Developer Profile

Flipbox Addon for Elementor Developer Profile

dragwyb

2 plugins · 300 total installs

88
trust score
Avg Security Score
100/100
Avg Patch Time
46 days
View full developer profile
Detection Fingerprints

How We Detect Flipbox Addon for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ultimate-flipbox-addon-for-elementor/admin/controls/assets/css/ufae-control.min.css
Version Parameters
ultimate-flipbox-addon-for-elementor/admin/controls/assets/css/ufae-control.min.css?ver=ultimate-flipbox-addon-for-elementor/assets/css/ufae-frontend.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
ufae-flipbox-itemufae-flipbox-wrap
Data Attributes
data-animationdata-effectdata-duration
JS Globals
UFAE
FAQ

Frequently Asked Questions about Flipbox Addon for Elementor