Elementor

wpdeeply.com/plugins/elementor/
MEDIUM WPDeeply risk rating
Active installations
10 million+
WordPress.org status
Active
Known vulnerabilities
Many, historically
Open unresolved
0 in current release
Last vulnerability
Findings appear regularly
PHP compatibility
PHP 7.4+ supported
Maintenance frequency
Active — frequent releases
WPDeeply recommendationSafe to keep if you update promptly. Audit your Elementor add-ons separately — that is where the real risk usually sits.

Data reviewed August 2026. Version numbers move weekly — the WordPress.org listing linked in the sidebar is always authoritative for the current release.

Current security status

Elementor is actively maintained with frequent releases and a responsive security process. WPDeeply rates it MEDIUM — not because the plugin is poorly built, but because of what it is: an enormous editing framework on ten million sites, with a vast third-party add-on ecosystem.

Why MEDIUM rather than LOW

  • Scale and complexity mean a steady stream of findings, most requiring some level of authentication.
  • Sites with contributor or subscriber registration are exposed to a class of Elementor findings that would otherwise be low impact.
  • The add-on ecosystem is the recurring problem. Third-party widget packs are smaller projects with slower patch cycles, and several of the most serious incidents in the Elementor world have come from add-ons rather than from Elementor itself.

Security history

Elementor has had multiple disclosed vulnerabilities over the years, overwhelmingly patched quickly in the following release. The pattern is normal for a plugin of this size and, on its own, is not a reason to avoid it — a plugin with a long history of promptly fixed issues usually means people are looking.

What to actually watch

  • Update Elementor and Elementor Pro promptly. Pro does not update through WordPress.org, so it needs its own attention.
  • List every Elementor add-on you have and check each one — the checker takes seconds per plugin.
  • Turn off open registration unless you need it.

Recommendation

Keep it if you use it. If you inherited a site where Elementor is installed but the pages are not built with it, that is dead weight on a large attack surface — see should you delete inactive plugins.