Widgetkits Security & Risk Analysis

wordpress.org/plugins/widgetkits

The Widgetkits is an Elementor helping plugin that will make your designing work easier.

10 active installs v1.1.1 PHP 5.6+ WP 4.7+ Updated Apr 12, 2021
elementorelementor-addonelementor-addonselementor-widgetwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Widgetkits Safe to Use in 2026?

Generally Safe

Score 85/100

Widgetkits has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of the 'widgetkits' v1.1.1 plugin reveals a generally positive security posture. The absence of any identified attack surface points, dangerous functions, file operations, external HTTP requests, or taint analysis issues is a significant strength. The plugin also demonstrates good practices by exclusively using prepared statements for SQL queries and ensuring a high percentage of output is properly escaped, minimizing risks associated with common web vulnerabilities like SQL injection and Cross-Site Scripting.

The plugin's vulnerability history is also exceptionally clean, with no recorded CVEs. This suggests a history of responsible development and patching, or a lack of significant past security flaws. The fact that there are no unpatched vulnerabilities further solidifies this perception. However, the complete absence of nonce checks and capability checks across all entry points (which are noted as zero, so this is theoretical if entry points existed) is a potential concern. While there are no active entry points to exploit, if future versions introduce new functionalities that create an attack surface, the lack of these fundamental security mechanisms could become a critical weakness.

In conclusion, 'widgetkits' v1.1.1 appears to be a secure plugin based on the provided data, with excellent adherence to secure coding practices for the limited functionality analyzed. The lack of identified vulnerabilities and a clean attack surface are strong indicators of a well-developed plugin. The primary area for vigilance would be to ensure that any future expansion of the plugin's capabilities includes robust authentication and authorization checks, such as nonce and capability checks, to maintain this high level of security.

Key Concerns

  • No Nonce checks found
  • No Capability checks found
Vulnerabilities
None known

Widgetkits Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Widgetkits Release Timeline

v1.1.1Current
v1.1.0
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Widgetkits Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
177 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped189 total outputs
Attack Surface

Widgetkits Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actioninitbase.php:28
actionplugins_loadedbase.php:29
actionadmin_noticesbase.php:42
actionadmin_noticesbase.php:47
actionadmin_noticesbase.php:53
actionelementor/widgets/widgets_registeredbase.php:58
actionelementor/elements/categories_registeredbase.php:59
actionelementor/editor/after_enqueue_scriptsbase.php:60
actionwp_enqueue_scriptsbase.php:61
actionelementor/frontend/before_register_scriptsbase.php:62
actionelementor/element/after_section_endextensions\custom-css.php:26
actionelementor/element/parse_cssextensions\custom-css.php:30
actionadmin_enqueue_scriptsinc\Clasess\class-widgetkits-about.php:24
actionwidgets_initinc\Clasess\class-widgetkits-about.php:300
actionwidgets_initinc\Clasess\class-widgetkits-recent-post.php:142
actionadmin_enqueue_scriptsinc\Clasess\class-widgetkits-socail.php:24
actionwidgets_initinc\Clasess\class-widgetkits-socail.php:250
actionwp_enqueue_scriptsinc\sidebar-widget-file.php:12
Maintenance & Trust

Widgetkits Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedApr 12, 2021
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Widgetkits Developer Profile

msakib

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Widgetkits

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/widgetkits/assets/vendor/themify-icons/themify-icons.css/wp-content/plugins/widgetkits/assets/css/widget-style.css/wp-content/plugins/widgetkits/assets/js/sidebar-widget.js/wp-content/plugins/widgetkits/assets/js/editor.js
Script Paths
/wp-content/plugins/widgetkits/assets/js/sidebar-widget.js/wp-content/plugins/widgetkits/assets/js/editor.js
Version Parameters
widgetkits/style.css?ver=widgetkits/sidebar-widget.js?ver=widgetkits/editor.js?ver=

HTML / DOM Fingerprints

CSS Classes
widgetkits-sidebar-widget-area
Data Attributes
data-widgetkits-id
JS Globals
WidgetkitsAbout
FAQ

Frequently Asked Questions about Widgetkits