WP-Stateless – Elementor Website Builder Addon Security & Risk Analysis

wordpress.org/plugins/wp-stateless-elementor-website-builder-addon

Provides compatibility between the Elementor Website Builder and the WP-Stateless plugins.

200 active installs v0.0.4 PHP 8.0+ WP 5.0+ Updated Oct 18, 2024
elementor-website-builderelementor-website-builder-addon-extensiongoogle-cloud-storagestatelesswp-stateless
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP-Stateless – Elementor Website Builder Addon Safe to Use in 2026?

Generally Safe

Score 92/100

WP-Stateless – Elementor Website Builder Addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "wp-stateless-elementor-website-builder-addon" plugin v0.0.4 exhibits a concerning security posture due to a significant number of unprotected entry points. While the static analysis indicates a lack of dangerous functions, raw SQL queries, file operations, external requests, and potential output escaping issues, the presence of two AJAX handlers without authentication checks is a critical weakness. This means that any user, regardless of their role or permissions, could potentially trigger these AJAX actions, opening the door for unauthorized operations or information disclosure.

The vulnerability history shows no recorded CVEs, which is a positive sign. However, this alone does not negate the risks identified in the code. The absence of taint analysis results is neutral, as it might imply no such flows were detected or the analysis tooling had limitations. The plugin demonstrates good practices by not bundling external libraries and by utilizing prepared statements for SQL queries, but these strengths are overshadowed by the critical exposure of AJAX endpoints.

In conclusion, while the plugin avoids some common pitfalls, the unprotected AJAX handlers represent a significant and immediate security risk. The lack of explicit capability checks and nonce validation on these entry points makes them prime targets for exploitation. Further investigation into the functionality of these AJAX handlers is crucial to understand the full impact of this vulnerability.

Key Concerns

  • AJAX handlers without auth checks
  • Lack of nonce checks on AJAX handlers
  • Lack of capability checks on AJAX handlers
Vulnerabilities
None known

WP-Stateless – Elementor Website Builder Addon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP-Stateless – Elementor Website Builder Addon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface
2 unprotected

WP-Stateless – Elementor Website Builder Addon Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_elementor_pro_forms_send_formclass-elementor.php:39
noprivwp_ajax_elementor_pro_forms_send_formclass-elementor.php:40
WordPress Hooks 15
actionelementor/core/files/clear_cacheclass-elementor.php:35
actionsave_postclass-elementor.php:36
actiondeleted_postclass-elementor.php:37
actionsm::pre::sync::nonMediaFilesclass-elementor.php:38
actionelementor_pro/forms/processclass-elementor.php:41
filterset_url_schemeclass-elementor.php:43
filterelementor/settings/general/success_response_dataclass-elementor.php:44
filtersm:sync::syncArgsclass-elementor.php:45
filtersm:sync::nonMediaFilesclass-elementor.php:46
filterelementor_pro/forms/upload_pathclass-elementor.php:47
filterelementor_pro/forms/upload_urlclass-elementor.php:48
filterelementor_pro/icons_manager/custom_icons/dirclass-elementor.php:49
filterelementor_pro/icons_manager/custom_icons/urlclass-elementor.php:50
actionplugins_loadedwp-stateless-elementor-addon.php:18
filterplugin_row_metawp-stateless-elementor-addon.php:25
Maintenance & Trust

WP-Stateless – Elementor Website Builder Addon Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 18, 2024
PHP min version8.0
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

WP-Stateless – Elementor Website Builder Addon Developer Profile

UDX Usability Dynamics

15 plugins · 5K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
322 days
View full developer profile
Detection Fingerprints

How We Detect WP-Stateless – Elementor Website Builder Addon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-stateless-elementor-website-builder-addon/vendor/wpcloud/stateless-media/src/Compatibility/elementor-compatibility.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP-Stateless – Elementor Website Builder Addon