Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages Security & Risk Analysis

wordpress.org/plugins/unlimited-elementor-inner-sections-by-boomdevs

Lightweight Elementor Addons plugin with essential Elementor widgets: Accordion, Tabs, CTA, Pricing Table, Testimonials, Post Grid, forms & more.

6K active installs v1.2.0 PHP 7.4+ WP 6.0+ Updated Feb 27, 2026
accordionelementorelementor-addonelementor-widgetstabs
99
A · Safe
CVEs total2
Unpatched0
Last CVEApr 11, 2024
Safety Verdict

Is Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages Safe to Use in 2026?

Generally Safe

Score 99/100

Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Apr 11, 2024Updated 1mo ago
Risk Assessment

The "unlimited-elementor-inner-sections-by-boomdevs" plugin v1.2.0 presents a mixed security posture. While it demonstrates good practices in terms of output escaping (96%) and largely utilizes prepared statements for SQL queries (80%), there are significant concerns regarding its attack surface. Specifically, 5 out of 10 AJAX handlers lack authentication checks, creating potential entry points for unauthorized actions. The taint analysis shows 2 flows with unsanitized paths, although they did not reach critical or high severity, they still represent a risk. The plugin's vulnerability history is also noteworthy; it has 2 known medium severity CVEs, with the last one being recent (April 2024), indicating a pattern of past security issues, particularly around missing authorization. Although there are no currently unpatched vulnerabilities, this history suggests a need for vigilant patching and code review. In conclusion, while the plugin has strengths in data handling, the presence of unprotected AJAX endpoints and past vulnerabilities warrants caution and proactive security management.

Key Concerns

  • Unprotected AJAX handlers
  • Flows with unsanitized paths
  • Medium severity CVEs in history
Vulnerabilities
2

Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-32110medium · 4.3Missing Authorization

Appsero <= 2.0.0 - Missing Authorization via handle_optin_optout

Apr 11, 2024 Patched in 1.0.5 (588d)

Appsero <= 1.2.1 - Missing Authorization

Dec 16, 2022 Patched in 1.0.2 (699d)
Code Analysis
Analyzed Mar 16, 2026

Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
4 prepared
Unescaped Output
39
887 escaped
Nonce Checks
7
Capability Checks
12
File Operations
2
External Requests
2
Bundled Libraries
0

SQL Query Safety

80% prepared5 total queries

Output Escaping

96% escaped926 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
handle_load_posts (includes\Ajax\PostGridAjaxHandler.php:21)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
5 unprotected

Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages Attack Surface

Entry Points10
Unprotected5

AJAX Handlers 10

authwp_ajax_pea_save_widgetsincludes\Admin\Admin.php:57
authwp_ajax_pea_get_plugin_changelogincludes\Admin\Admin.php:58
authwp_ajax_get_author_by_post_typeincludes\Plugin.php:172
authwp_ajax_get_category_by_post_typeincludes\Plugin.php:173
authwp_ajax_get_tag_by_post_typeincludes\Plugin.php:174
authwp_ajax_pea_upload_animation_fileincludes\Plugin.php:175
authwp_ajax_pea_rive_wasmincludes\Plugin.php:176
noprivwp_ajax_pea_rive_wasmincludes\Plugin.php:177
authwp_ajax_pea_load_postsincludes\Plugin.php:178
noprivwp_ajax_pea_load_postsincludes\Plugin.php:179
WordPress Hooks 41
actionadmin_noticeseuis.php:44
actionadmin_menuincludes\Admin\Admin.php:54
actionadmin_enqueue_scriptsincludes\Admin\Admin.php:55
actionrest_api_initincludes\Admin\Admin.php:56
filterwp_redirectincludes\Admin\Admin.php:59
filterupdate_footerincludes\Admin\Admin.php:95
filteradmin_footer_textincludes\Admin\Admin.php:96
actionplugins_loadedincludes\Plugin.php:62
actionplugins_loadedincludes\Plugin.php:63
actionplugins_loadedincludes\Plugin.php:64
actionelementor/initincludes\Plugin.php:65
actioncurrent_screenincludes\Plugin.php:69
actionadmin_initincludes\Plugin.php:71
actionadmin_noticesincludes\Plugin.php:133
actionadmin_noticesincludes\Plugin.php:139
actionadmin_noticesincludes\Plugin.php:145
actionwp_enqueue_scriptsincludes\Plugin.php:160
actionwp_enqueue_scriptsincludes\Plugin.php:161
filterscript_loader_tagincludes\Plugin.php:162
actionelementor/widgets/registerincludes\Plugin.php:163
actionelementor/elements/categories_registeredincludes\Plugin.php:164
actionelementor/frontend/after_enqueue_stylesincludes\Plugin.php:165
actionelementor/frontend/after_register_scriptsincludes\Plugin.php:166
actionwp_enqueue_scriptsincludes\Plugin.php:167
actionelementor/editor/after_enqueue_scriptsincludes\Plugin.php:169
actionelementor/editor/after_enqueue_stylesincludes\Plugin.php:170
filterelementor/editor/localize_settingsincludes\Plugin.php:171
filtermime_typesincludes\Plugin.php:180
filterupload_mimesincludes\Plugin.php:181
filterwp_handle_upload_overridesincludes\Plugin.php:182
filterwp_handle_uploadincludes\Plugin.php:183
filterwp_check_filetype_and_extincludes\Plugin.php:184
filtersite_option_upload_filetypesincludes\Plugin.php:185
filterelementor/files/allow_unfiltered_uploadincludes\Plugin.php:186
actionadmin_noticesincludes\Plugin.php:461
actionadmin_noticesincludes\Ueis\BoomDevsNotificationWidgetInner.php:18
actionadmin_enqueue_scriptsincludes\Ueis\BoomDevsNotificationWidgetInner.php:19
actionsave_postincludes\Ueis\BoomDevsNotificationWidgetInner.php:20
actionelementor/editor/after_enqueue_scriptsincludes\Ueis\UnlimitedElementorInnerSections.php:45
actionelementor/element/after_section_endincludes\Utils\WidgetCustomCss.php:35
actionelementor/element/parse_cssincludes\Utils\WidgetCustomCss.php:43
Maintenance & Trust

Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 27, 2026
PHP min version7.4
Downloads61K

Community Trust

Rating84/100
Number of ratings5
Active installs6K
Developer Profile

Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages Developer Profile

WP Messiah

12 plugins · 26K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
132 days
View full developer profile
Detection Fingerprints

How We Detect Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/unlimited-elementor-inner-sections-by-boomdevs/assets/css/admin.css/wp-content/plugins/unlimited-elementor-inner-sections-by-boomdevs/assets/js/admin.js/wp-content/plugins/unlimited-elementor-inner-sections-by-boomdevs/assets/images/love-favorite.svg/wp-content/plugins/unlimited-elementor-inner-sections-by-boomdevs/assets/images/wp-messiah-logo.png
Script Paths
/wp-content/plugins/unlimited-elementor-inner-sections-by-boomdevs/appsero/src/Client.php
Version Parameters
unlimited-elementor-inner-sections-by-boomdevs/assets/css/admin.css?ver=unlimited-elementor-inner-sections-by-boomdevs/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
prime-elementor-addons-admin-footerwp-messiah-logofooter-logo
HTML Comments
<!-- Currently plugin version. --><!-- Start at version 1.0.0 and use SemVer - https://semver.org --><!-- Rename this for your plugin and update it as you release new versions. --><!-- Currently plugin version. -->+8 more
Data Attributes
id="prime-elementor-addons-admin"
JS Globals
PEA_PLUGIN_URLPEA_PLUGIN_PATHPEA_UEIS_BACKEND_URLPEA_PLUGIN_FILE
REST Endpoints
/wp-json/notification-api/v1/get
FAQ

Frequently Asked Questions about Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages