Which Elementor Addon Security & Risk Analysis

wordpress.org/plugins/which-addon-for-elementor

Which Elementor Addon is a simple lightweight plugin. It will help you to find out the widget’s plugin name that you have used in creating your web pa …

600 active installs v1.3.0 PHP 7.0+ WP 6.0+ Updated Oct 28, 2025
editorelementorlanding-pagepage-builder
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Which Elementor Addon Safe to Use in 2026?

Generally Safe

Score 100/100

Which Elementor Addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The plugin "which-addon-for-elementor" v1.3.0 exhibits a generally strong security posture based on the provided static analysis. The absence of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events, combined with 100% usage of prepared statements for SQL queries, indicates a good practice in preventing common web vulnerabilities. The capability checks present also suggest an awareness of access control, although the lack of nonce checks is a notable absence, especially if any form of dynamic content generation or modification is possible through other means.

The static analysis reveals no critical or high-severity issues within taint flows or dangerous functions. However, the fact that only 50% of output escaping is properly done is a concern. While the total number of outputs is small (2), any unescaped output can lead to Cross-Site Scripting (XSS) vulnerabilities, especially if user-controlled data is ever involved in rendering these outputs. The vulnerability history being entirely clear is a positive sign, suggesting the developers have a good track record, but it does not negate the need for careful code review for potential vulnerabilities.

In conclusion, the plugin appears to be built with security in mind, particularly concerning database interactions and reducing its direct attack surface. The primary area of concern is the partial output escaping, which warrants further investigation to ensure no XSS vulnerabilities exist. The absence of nonce checks also presents a potential weakness if any actions are performed without sufficient client-side protection. Overall, it presents a low to moderate risk profile, but the unescaped output is a critical point to address.

Key Concerns

  • 50% of outputs not properly escaped
  • No nonce checks present
Vulnerabilities
None known

Which Elementor Addon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Which Elementor Addon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
1 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped2 total outputs
Attack Surface

Which Elementor Addon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_noticeswhich-addon-for-elementor.php:85
actionadmin_noticeswhich-addon-for-elementor.php:91
actionadmin_initwhich-addon-for-elementor.php:95
actionwp_enqueue_scriptswhich-addon-for-elementor.php:96
actionelementor/admin/after_create_settings/elementor-toolswhich-addon-for-elementor.php:108
Maintenance & Trust

Which Elementor Addon Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 28, 2025
PHP min version7.0
Downloads10K

Community Trust

Rating100/100
Number of ratings24
Active installs600
Developer Profile

Which Elementor Addon Developer Profile

Md Obidullah (obiPlabon)

3 plugins · 4K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Which Elementor Addon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/which-addon-for-elementor/assets/css/script.css
Script Paths
/wp-content/plugins/which-addon-for-elementor/assets/js/script.js

HTML / DOM Fingerprints

CSS Classes
which-addon-for-elementor-tooltip
Data Attributes
data-which-addon-for-elementor-plugindata-which-addon-for-elementor-widget
JS Globals
which_addon_for_elementor_settings
FAQ

Frequently Asked Questions about Which Elementor Addon