
Which Elementor Addon Security & Risk Analysis
wordpress.org/plugins/which-addon-for-elementorWhich Elementor Addon is a simple lightweight plugin. It will help you to find out the widget’s plugin name that you have used in creating your web pa …
Is Which Elementor Addon Safe to Use in 2026?
Generally Safe
Score 100/100Which Elementor Addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "which-addon-for-elementor" v1.3.0 exhibits a generally strong security posture based on the provided static analysis. The absence of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events, combined with 100% usage of prepared statements for SQL queries, indicates a good practice in preventing common web vulnerabilities. The capability checks present also suggest an awareness of access control, although the lack of nonce checks is a notable absence, especially if any form of dynamic content generation or modification is possible through other means.
The static analysis reveals no critical or high-severity issues within taint flows or dangerous functions. However, the fact that only 50% of output escaping is properly done is a concern. While the total number of outputs is small (2), any unescaped output can lead to Cross-Site Scripting (XSS) vulnerabilities, especially if user-controlled data is ever involved in rendering these outputs. The vulnerability history being entirely clear is a positive sign, suggesting the developers have a good track record, but it does not negate the need for careful code review for potential vulnerabilities.
In conclusion, the plugin appears to be built with security in mind, particularly concerning database interactions and reducing its direct attack surface. The primary area of concern is the partial output escaping, which warrants further investigation to ensure no XSS vulnerabilities exist. The absence of nonce checks also presents a potential weakness if any actions are performed without sufficient client-side protection. Overall, it presents a low to moderate risk profile, but the unescaped output is a critical point to address.
Key Concerns
- 50% of outputs not properly escaped
- No nonce checks present
Which Elementor Addon Security Vulnerabilities
Which Elementor Addon Code Analysis
Output Escaping
Which Elementor Addon Attack Surface
WordPress Hooks 5
Maintenance & Trust
Which Elementor Addon Maintenance & Trust
Maintenance Signals
Community Trust
Which Elementor Addon Alternatives
Elementor Website Builder – More Than Just a Page Builder
elementor
The Elementor Website Builder has it all: drag and drop page builder, pixel perfect design, mobile responsive editing, and more. Get started now!
TemplateSpare – 1000+ WordPress Starter Templates & Full Site Migration Tool | 1-Click Import/Export & No-Code Builder
templatespare
Imagine this... You’re planning your new website. You’re excited at first—but then reality hits. The design takes months. You wait for the developer t …
DragDropr – Visual Drag & Drop Page Builder
dragdropr
DragDropr is a What-You-See-Is-What-You-REALLY-Get visual editor.
Multi-step Forms FREE (for Elementor)
multi-step-forms-free-for-elementor
A simple plugin that streamlines the creation of multistep (or multiple page) forms to an easy drag-and-drop through the power of Elementor Pro.
Page builder for Posts – Mong9 Editor
mong9-editor
The most advanced frontend drag & drop content editor. Mong9 Editor is a responsive page builder which can be used to extend the Classic Editor.
Which Elementor Addon Developer Profile
3 plugins · 4K total installs
How We Detect Which Elementor Addon
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/which-addon-for-elementor/assets/css/script.css/wp-content/plugins/which-addon-for-elementor/assets/js/script.jsHTML / DOM Fingerprints
which-addon-for-elementor-tooltipdata-which-addon-for-elementor-plugindata-which-addon-for-elementor-widgetwhich_addon_for_elementor_settings