
CoDesigner – All in One Elementor WooCommerce Builder Security & Risk Analysis
wordpress.org/plugins/woolementorDesign stunning WooCommerce sites that sell with 94+ Widgets, 14+ Modules, & 150+ Templates of CoDesigner Elementor WooCommerce addon.
Is CoDesigner – All in One Elementor WooCommerce Builder Safe to Use in 2026?
High Risk
Score 47/100CoDesigner – All in One Elementor WooCommerce Builder carries significant security risk with 4 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
Woolementor v4.29 presents a mixed security posture. The plugin demonstrates good practices in its use of prepared statements for SQL queries and a high percentage of properly escaped output. However, significant concerns arise from its attack surface, with one AJAX handler lacking authentication checks, and a critical taint flow identified. The presence of the `unserialize` function, while not directly flagged as a vulnerability in the static analysis, is a known risk factor, especially when combined with untrusted data. The plugin's vulnerability history is a major red flag, with four known CVEs, two of which remain unpatched. The prevalence of Critical and Medium severity vulnerabilities, including Deserialization of Untrusted Data and Cross-site Scripting, coupled with a recent vulnerability in late 2025, suggests a recurring pattern of security weaknesses that require prompt attention. While the plugin benefits from secure coding practices in some areas, the combination of an unprotected entry point, a critical taint flow, and a history of significant, unpatched vulnerabilities points to a moderate to high risk profile.
Key Concerns
- Unprotected AJAX handler
- Critical severity taint flow
- Unpatched critical CVE
- Unpatched medium CVE (x2)
- Dangerous function 'unserialize'
CoDesigner – All in One Elementor WooCommerce Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
CoDesigner <= 4.26 - Missing Authorization
CoDesigner WooCommerce Builder for Elementor <= 4.21 - Authenticated (Author+) Stored Cross-Site Scripting
CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More <= 4.4.1 - Unauthenticated PHP Object Injection
CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More <= 4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
CoDesigner – All in One Elementor WooCommerce Builder Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
CoDesigner – All in One Elementor WooCommerce Builder Attack Surface
AJAX Handlers 1
WordPress Hooks 5
Scheduled Events 2
Maintenance & Trust
CoDesigner – All in One Elementor WooCommerce Builder Maintenance & Trust
Maintenance Signals
Community Trust
CoDesigner – All in One Elementor WooCommerce Builder Alternatives
ShopBuilder – WooCommerce Builder For Elementor
shopbuilder
WooCommerce builder for Elementor includes 80+ widgets, WooCommerce templates, quick view, compare, wishlist, shop & archive page builder and more.
ShopMaker – Elementor WooCommerce Builder, Widgets & Templates
shopmaker
Create fully custom WooCommerce pages with Elementor: 50+ dedicated WooCommerce widgets and beautiful pre-designed templates.
UnikForce Elementor WooCommerce Builder
unikforce-elementor-woocommerce
Enhance your Elementor page building experience with elementor dynamic woocommerce builder. Add power to your woocommerce builder using our easy-to-us …
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution
shopengine
WooCommerce builder for Elementor and Gutenberg. It offers product templates, product sliders, shopping cart, quick view, Woo wishlist, product filter …
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
woolentor-addons
ShopLentor – More than a WooCommerce builder. A complete growth plugin to boost conversions, UX, and sales for your store.
CoDesigner – All in One Elementor WooCommerce Builder Developer Profile
10 plugins · 41K total installs
How We Detect CoDesigner – All in One Elementor WooCommerce Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woolementor/assets/css/frontend.css/wp-content/plugins/woolementor/assets/css/admin.css/wp-content/plugins/woolementor/assets/js/frontend.js/wp-content/plugins/woolementor/assets/js/admin.js/wp-content/plugins/woolementor/assets/js/frontend.js/wp-content/plugins/woolementor/assets/js/admin.jswoolementor/assets/css/frontend.css?ver=woolementor/assets/css/admin.css?ver=woolementor/assets/js/frontend.js?ver=woolementor/assets/js/admin.js?ver=HTML / DOM Fingerprints
woolementor-frontendwoolementorFrontend