
WP-Stateless – Elementor Website Builder Addon Security & Risk Analysis
wordpress.org/plugins/wp-stateless-elementor-website-builder-addonProvides compatibility between the Elementor Website Builder and the WP-Stateless plugins.
Is WP-Stateless – Elementor Website Builder Addon Safe to Use in 2026?
Generally Safe
Score 92/100WP-Stateless – Elementor Website Builder Addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-stateless-elementor-website-builder-addon" plugin v0.0.4 exhibits a concerning security posture due to a significant number of unprotected entry points. While the static analysis indicates a lack of dangerous functions, raw SQL queries, file operations, external requests, and potential output escaping issues, the presence of two AJAX handlers without authentication checks is a critical weakness. This means that any user, regardless of their role or permissions, could potentially trigger these AJAX actions, opening the door for unauthorized operations or information disclosure.
The vulnerability history shows no recorded CVEs, which is a positive sign. However, this alone does not negate the risks identified in the code. The absence of taint analysis results is neutral, as it might imply no such flows were detected or the analysis tooling had limitations. The plugin demonstrates good practices by not bundling external libraries and by utilizing prepared statements for SQL queries, but these strengths are overshadowed by the critical exposure of AJAX endpoints.
In conclusion, while the plugin avoids some common pitfalls, the unprotected AJAX handlers represent a significant and immediate security risk. The lack of explicit capability checks and nonce validation on these entry points makes them prime targets for exploitation. Further investigation into the functionality of these AJAX handlers is crucial to understand the full impact of this vulnerability.
Key Concerns
- AJAX handlers without auth checks
- Lack of nonce checks on AJAX handlers
- Lack of capability checks on AJAX handlers
WP-Stateless – Elementor Website Builder Addon Security Vulnerabilities
WP-Stateless – Elementor Website Builder Addon Code Analysis
WP-Stateless – Elementor Website Builder Addon Attack Surface
AJAX Handlers 2
WordPress Hooks 15
Maintenance & Trust
WP-Stateless – Elementor Website Builder Addon Maintenance & Trust
Maintenance Signals
Community Trust
WP-Stateless – Elementor Website Builder Addon Alternatives
WP-Stateless – Gravity Forms Addon
wp-stateless-gravity-forms-addon
Provides compatibility between the Gravity Forms and the WP-Stateless plugins.
WP-Stateless – WooCommerce Addon
wp-stateless-woocommerce-addon
Provides compatibility between the WooCommerce and the WP-Stateless plugins.
WP-Stateless – LiteSpeed Cache Addon
wp-stateless-litespeed-cache-addon
Provides compatibility between the LiteSpeed Cache and the WP-Stateless plugins.
WP-Stateless – Divi Theme Addon
wp-stateless-divi-theme-addon
Provides compatibility between the Divi theme and the WP-Stateless plugin.
WP-Stateless – SiteOrigin Widgets Bundle Addon
wp-stateless-siteorigin-widgets-bundle-addon
Provides compatibility between the SiteOrigin Widgets Bundle and the WP-Stateless plugins.
WP-Stateless – Elementor Website Builder Addon Developer Profile
15 plugins · 5K total installs
How We Detect WP-Stateless – Elementor Website Builder Addon
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-stateless-elementor-website-builder-addon/vendor/wpcloud/stateless-media/src/Compatibility/elementor-compatibility.php