
X Addons for Elementor Security & Risk Analysis
wordpress.org/plugins/x-addons-elementorX Addons - A powerful collection of creative and lightweight Elementor widgets that help you design beautiful websites faster and easier.
Is X Addons for Elementor Safe to Use in 2026?
Use With Caution
Score 52/100X Addons for Elementor has 2 unpatched vulnerabilities. Evaluate alternatives or apply available mitigations.
The static analysis of x-addons-elementor v1.0.23 reveals a strong adherence to secure coding practices in its immediate implementation. The absence of identified dangerous functions, file operations, external HTTP requests, and the exclusive use of prepared statements for SQL queries are positive indicators. Furthermore, the high percentage of properly escaped output suggests a good effort to mitigate cross-site scripting vulnerabilities within the directly analyzed code. However, the complete lack of entry points like AJAX handlers, REST API routes, shortcodes, and cron events in the static analysis is unusual and might indicate these features are handled elsewhere or that the analysis scope was limited.
The primary concern stems from the plugin's vulnerability history. With a total of 4 known CVEs, and 2 of them currently unpatched, this plugin presents a significant risk. The common vulnerability types being Missing Authorization and Cross-site Scripting, coupled with the medium severity of these historical issues, directly contradict the positive findings in the static analysis, suggesting past code may have been vulnerable or that current analysis missed critical aspects. The recency of the last vulnerability (2026-01-14) is also concerning and likely a typo or futuristic projection, indicating ongoing issues.
In conclusion, while the current version's static code exhibits good security hygiene in specific areas, the persistent history of unpatched vulnerabilities, particularly those related to authorization and XSS, overshadows these strengths. The presence of unpatched CVEs means active exploitation is possible. The plugin's reliance on potentially vulnerable historical code or areas not covered by static analysis warrants extreme caution. Users should prioritize updating to a version that has addressed all past CVEs.
Key Concerns
- Unpatched CVEs
- Missing Nonce Checks
- Missing Capability Checks
- Unusual lack of identified entry points in static analysis
X Addons for Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
X Addons for Elementor <= 1.0.23 - Missing Authorization
X Addons for Elementor <= 1.0.23 - Authenticated (Contributor+) Stored Cross-Site Scripting
X Addons for Elementor <= 1.0.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via Youtube Video ID Field
X Addons for Elementor <= 1.0.16 - Authenticated (Contributor+) Stored Cross-Site Scripting
X Addons for Elementor Release Timeline
X Addons for Elementor Code Analysis
Output Escaping
X Addons for Elementor Attack Surface
WordPress Hooks 8
Maintenance & Trust
X Addons for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
X Addons for Elementor Alternatives
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
premium-addons-for-elementor
Elementor Carousel, Mega Menu, Posts List/Slider, Media Gallery, WooCommerce Widgets, Display Conditions, Premade Templates & more.
Royal Addons for Elementor – Addons and Templates Kit for Elementor
royal-elementor-addons
Elementor templates, Header footer builder, Elementor Post Grid, Woocommerce Grid builder, Slider, Forms, Gallery, Nav menu addons, Elementor widgets.
X Addons for Elementor Developer Profile
2 plugins · 800 total installs
How We Detect X Addons for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/x-addons-elementor/assets/css/slick.css/wp-content/plugins/x-addons-elementor/assets/css/fancy-box.css/wp-content/plugins/x-addons-elementor/assets/css/odometer.css/wp-content/plugins/x-addons-elementor/assets/css/xa-styles.css/wp-content/plugins/x-addons-elementor/assets/js/slick.js/wp-content/plugins/x-addons-elementor/assets/js/odometer.js/wp-content/plugins/x-addons-elementor/assets/js/circle-progress.js/wp-content/plugins/x-addons-elementor/assets/js/fancy-box.js+2 more/wp-content/plugins/x-addons-elementor/assets/js/slick.js/wp-content/plugins/x-addons-elementor/assets/js/odometer.js/wp-content/plugins/x-addons-elementor/assets/js/circle-progress.js/wp-content/plugins/x-addons-elementor/assets/js/fancy-box.js/wp-content/plugins/x-addons-elementor/assets/js/typed.js/wp-content/plugins/x-addons-elementor/assets/js/plugin-active.jsx-addons-elementor/assets/css/slick.css?ver=1.0x-addons-elementor/assets/css/fancy-box.css?ver=3.5.7x-addons-elementor/assets/css/odometer.css?ver=1.0x-addons-elementor/assets/css/xa-styles.css?ver=1.0x-addons-elementor/assets/js/slick.js?ver=2.0x-addons-elementor/assets/js/odometer.js?ver=1.0x-addons-elementor/assets/js/circle-progress.js?ver=1.2.2x-addons-elementor/assets/js/fancy-box.js?ver=3.5.7x-addons-elementor/assets/js/typed.js?ver=1.0x-addons-elementor/assets/js/plugin-active.js?ver=1.0HTML / DOM Fingerprints
xa-slider-wrapXEA_Ajax_Url