WPoperation Elementor Addons Security & Risk Analysis

wordpress.org/plugins/wpop-elementor-addons

This is a plugin for WPoperation WordPress Themes. The theme contains elements of elementor.

1K active installs v1.1.9 PHP + WP 3.6+ Updated Oct 8, 2024
arrivalecommerceelementoropstorewoocommerce
71
B · Generally Safe
CVEs total1
Unpatched1
Last CVEApr 1, 2025
Safety Verdict

Is WPoperation Elementor Addons Safe to Use in 2026?

Mostly Safe

Score 71/100

WPoperation Elementor Addons is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Apr 1, 2025Updated 1yr ago
Risk Assessment

The static analysis for wpop-elementor-addons v1.1.9 reveals a generally good security posture, with no identified dangerous functions, SQL queries using prepared statements, or file operations. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points suggests a limited attack surface. However, concerns arise from the complete lack of nonce checks and capability checks, which are critical for securing sensitive actions within WordPress. Furthermore, 21% of output is not properly escaped, posing a potential Cross-Site Scripting (XSS) risk, though the absence of taint analysis data makes it difficult to quantify the severity of this.

The vulnerability history is a significant concern. The presence of one unpatched medium severity CVE, last discovered on 2025-04-01, indicates a lingering security flaw. The common vulnerability type being XSS further reinforces the risk associated with the unescaped output identified in the static analysis. While the plugin demonstrates strengths in its limited attack surface and secure handling of SQL, the lack of robust authorization checks and the unpatched vulnerability significantly weaken its overall security. Users should be cautious until the unpatched CVE is addressed and the output escaping is fully implemented.

Key Concerns

  • Unpatched CVE (medium severity)
  • Output escaping concerns (21% unescaped)
  • No nonce checks
  • No capability checks
Vulnerabilities
1 published

WPoperation Elementor Addons Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-31823medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WPoperation Elementor Addons <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 1, 2025Unpatched
Version History

WPoperation Elementor Addons Release Timeline

v1.1.9Current1 CVE
v1.1.81 CVE
v1.1.71 CVE
v1.1.61 CVE
v1.1.51 CVE
v1.1.41 CVE
v1.1.31 CVE
v1.1.21 CVE
v1.1.11 CVE
v1.1.01 CVE
v1.0.91 CVE
v1.0.81 CVE
v1.0.71 CVE
v1.0.61 CVE
v1.0.51 CVE
v1.0.41 CVE
v1.0.31 CVE
Code Analysis
Analyzed Mar 16, 2026

WPoperation Elementor Addons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
64
247 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

79% escaped311 total outputs
Attack Surface

WPoperation Elementor Addons Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
filternav_menu_link_attributeselements\common\advanced-menu.php:1451
filternav_menu_submenu_css_classelements\common\advanced-menu.php:1452
filternav_menu_item_idelements\common\advanced-menu.php:1453
actionelementor/initincludes\helpers.php:23
actioninitwpop-elementor-addons.php:31
actionadmin_noticeswpop-elementor-addons.php:33
actionwp_enqueue_scriptswpop-elementor-addons.php:35
actionelementor/widgets/widgets_registeredwpop-elementor-addons.php:36
actionadmin_initwpop-elementor-addons.php:37
Maintenance & Trust

WPoperation Elementor Addons Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 8, 2024
PHP min version
Downloads90K

Community Trust

Rating20/100
Number of ratings1
Active installs1K
Developer Profile

WPoperation Elementor Addons Developer Profile

wpoperations

11 plugins · 17K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
349 days
View full developer profile
Detection Fingerprints

How We Detect WPoperation Elementor Addons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpop-elementor-addons/assets/slick/slick.min.js/wp-content/plugins/wpop-elementor-addons/assets/isotope/isotope.pkgd.js/wp-content/plugins/wpop-elementor-addons/assets/countdown/jquery.countdown.min.js/wp-content/plugins/wpop-elementor-addons/assets/advanced-menu.js/wp-content/plugins/wpop-elementor-addons/assets/jquery-smartmenu.js/wp-content/plugins/wpop-elementor-addons/assets/wpopea-elements.js/wp-content/plugins/wpop-elementor-addons/assets/slick/slick.css/wp-content/plugins/wpop-elementor-addons/assets/slick/slick-theme.css+7 more
Script Paths
wpopea-el-slick-jswpopea-el-isotope-jswpopea-el-countdown-jswpopea-el-menu-jswpopea-el-smartmenu-jswpopea-el-js
Version Parameters
wpopea-el-slick-js?ver=1.1.9wpopea-el-isotope-js?ver=1.1.9wpopea-el-countdown-js?ver=1.1.9wpopea-el-menu-js?ver=1.1.9wpopea-el-smartmenu-js?ver=1.1.9wpopea-elements.js?ver=1.1.9slick.css?ver=1.1.9slick-theme.css?ver=1.1.9ticker.css?ver=1.1.9search.css?ver=1.1.9cat-drop.css?ver=1.1.9tiled-post.css?ver=1.1.9advanced-menu.css?ver=1.1.9single-post.css?ver=1.1.9wpopea-element.css?ver=1.1.9

HTML / DOM Fingerprints

CSS Classes
wpopea-advanced-menu
JS Globals
wpopea-el-smartmenu-jswpopea-el-menu-jswpopea-el-js
FAQ

Frequently Asked Questions about WPoperation Elementor Addons