- Active installations
- 10 million+
- WordPress.org status
- Active
- Known vulnerabilities
- Many, historically
- Open unresolved
- 0 in current release
- Last vulnerability
- Findings appear regularly
- PHP compatibility
- PHP 7.4+ supported
- Maintenance frequency
- Active — frequent releases
Data reviewed August 2026. Version numbers move weekly — the WordPress.org listing linked in the sidebar is always authoritative for the current release.
Current security status
Elementor is actively maintained with frequent releases and a responsive security process. WPDeeply rates it MEDIUM — not because the plugin is poorly built, but because of what it is: an enormous editing framework on ten million sites, with a vast third-party add-on ecosystem.
Why MEDIUM rather than LOW
- Scale and complexity mean a steady stream of findings, most requiring some level of authentication.
- Sites with contributor or subscriber registration are exposed to a class of Elementor findings that would otherwise be low impact.
- The add-on ecosystem is the recurring problem. Third-party widget packs are smaller projects with slower patch cycles, and several of the most serious incidents in the Elementor world have come from add-ons rather than from Elementor itself.
Security history
Elementor has had multiple disclosed vulnerabilities over the years, overwhelmingly patched quickly in the following release. The pattern is normal for a plugin of this size and, on its own, is not a reason to avoid it — a plugin with a long history of promptly fixed issues usually means people are looking.
What to actually watch
- Update Elementor and Elementor Pro promptly. Pro does not update through WordPress.org, so it needs its own attention.
- List every Elementor add-on you have and check each one — the checker takes seconds per plugin.
- Turn off open registration unless you need it.
Recommendation
Keep it if you use it. If you inherited a site where Elementor is installed but the pages are not built with it, that is dead weight on a large attack surface — see should you delete inactive plugins.