
WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More Security & Risk Analysis
wordpress.org/plugins/wpb-elementor-addonsA powerful collection of custom Elementor widgets and extensions to build advanced layouts with ease.
Is WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More Safe to Use in 2026?
Mostly Safe
Score 74/100WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More is generally safe to use. 4 past CVEs were resolved. Keep it updated.
The "wpb-elementor-addons" v1.7 plugin exhibits a mixed security posture. On one hand, the static analysis reveals strong adherence to secure coding practices in several areas. The complete absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. The high percentage of properly escaped output (92%) and the presence of a nonce check are also positive indicators, suggesting an effort to mitigate common vulnerabilities.
However, significant concerns arise from the plugin's vulnerability history and the lack of certain security checks. The fact that there are four known CVEs, with one currently unpatched, and all historically being medium severity Cross-Site Scripting (XSS) vulnerabilities, points to a recurring pattern of input sanitization issues. While no critical taint flows were detected in the current static analysis, the historical data suggests this is a persistent risk that has not been fully eradicated. The absence of capability checks on any entry points is also a notable weakness, as it means that even if entry points were discovered, they might not be properly restricted to authorized users.
In conclusion, while "wpb-elementor-addons" v1.7 demonstrates strengths in its secure coding implementation for certain aspects, the ongoing presence of unpatched vulnerabilities, particularly XSS, and the lack of capability checks present a significant risk. The developer needs to address the historical XSS issues comprehensively and ensure robust authorization checks are in place for all potential entry points in future releases. The current state is not ideal and requires attention to move towards a more secure posture.
Key Concerns
- Currently unpatched CVEs
- Medium severity CVE history
- Lack of capability checks
- Unescaped output (8% of outputs)
WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
WPB Elementor Addons <= 1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
WPB Elementor Addons <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
WPB Elementor Addons <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via url Parameter
WPB Elementor Addons <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More Code Analysis
Output Escaping
WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More Attack Surface
WordPress Hooks 21
Maintenance & Trust
WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More Maintenance & Trust
Maintenance Signals
Community Trust
WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More Alternatives
Qi Addons For Elementor
qi-addons-for-elementor
Qi Addons for Elementor is a comprehensive library of 60+ custom, flexible & easily styled Elementor widgets developed by Qode Interactive.
MT Addons for Elementor
mt-addons-for-elementor
MT Addons for Elementor with 50+ widgets, crafted by ModelTheme for dynamic, stylish website creation.
ACF Post Object Elementor List Widget
acf-post-object-elementor-list-widget
A WordPress Plugin that adds the ability to display the contents of an ACF Post Object field as a list of post links.
Wadi Addons for Elementor
wadi-addons-for-elementor
Wadi Addons for Elementor Page Builder provides a collection of quality Elementor Widgets which powers your Elementor Page Builder and takes your page …
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More Developer Profile
25 plugins · 40K total installs
How We Detect WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpb-elementor-addons/assets/css/wpb-elementor-addons.css/wp-content/plugins/wpb-elementor-addons/assets/js/wpb-elementor-addons.js/wp-content/plugins/wpb-elementor-addons/assets/js/wpb-elementor-addons.jswpb-elementor-addons/assets/css/wpb-elementor-addons.css?ver=wpb-elementor-addons/assets/js/wpb-elementor-addons.js?ver=HTML / DOM Fingerprints
wpb-ea-discount-noticedata-wpb-ea-editordata-wpb-ea-editor-contentWPB_EA_LOCALIZEwpb_ea_params