
aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder Security & Risk Analysis
wordpress.org/plugins/ablocksaBlocks is a Gutenberg-based website builder with 100+ free flexible blocks and powerful form solutions, allowing you to build any type of form!
Is aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder Safe to Use in 2026?
Mostly Safe
Score 74/100aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder is generally safe to use. 3 past CVEs were resolved. Keep it updated.
The ablocks plugin v2.7.7 exhibits a mixed security posture. While it demonstrates good practices in many areas, such as high percentages of prepared SQL statements and properly escaped output, significant concerns remain. The presence of two AJAX handlers without authentication checks presents a clear attack vector for unauthorized actions. The use of the `unserialize` function is a notable risk, as it can lead to Remote Code Execution if used with untrusted input. The plugin's history of three known CVEs, with one currently unpatched, and a pattern of Missing Authorization and Cross-Site Scripting vulnerabilities, indicates a recurring struggle with secure input handling and access control. Although taint analysis showed no critical or high severity flows, the historical context and the identified code-level weaknesses warrant caution.
Key Concerns
- Two AJAX handlers without authentication checks
- Use of dangerous function: unserialize
- One unpatched CVE of medium severity
- History of missing authorization vulnerabilities
- History of XSS vulnerabilities
aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
aBlocks – WordPress Gutenberg Blocks <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Settings Modification
aBlocks <= 1.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
aBlocks – WordPress Gutenberg Blocks <= 1.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 90
Maintenance & Trust
aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder Maintenance & Trust
Maintenance Signals
Community Trust
aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder Alternatives
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Superb Addons: Blocks, Patterns & Theme Designer for the Block Editor & FSE
superb-blocks
Create beautiful WordPress websites easily with 10+ blocks, 200+ patterns, 100+ pre-built pages, animations and Theme Designer. No coding needed!
GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor
gutenkit-blocks-addon
GutenKit – Ultimate no-code Gutenberg blocks to design stunning web pages and visually stunning posts in WordPress block editor.
aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder Developer Profile
7 plugins · 5K total installs
How We Detect aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ablocks/assets/css/frontend.css/wp-content/plugins/ablocks/assets/js/frontend.js/wp-content/plugins/ablocks/assets/css/blocks.style.build.css/wp-content/plugins/ablocks/assets/js/blocks.editor.build.js/wp-content/plugins/ablocks/assets/js/blocks.build.js/wp-content/plugins/ablocks/assets/css/theme-builder/frontend.css/wp-content/plugins/ablocks/assets/js/theme-builder/frontend.js/wp-content/plugins/ablocks/assets/css/blocks.style.css+3 more/wp-content/plugins/ablocks/assets/js/frontend.js/wp-content/plugins/ablocks/assets/js/blocks.editor.build.js/wp-content/plugins/ablocks/assets/js/blocks.build.js/wp-content/plugins/ablocks/assets/js/theme-builder/frontend.js/wp-content/plugins/ablocks/assets/js/blocks.js/wp-content/plugins/ablocks/assets/js/theme-builder/editor.jsablocks/assets/css/frontend.css?ver=ablocks/assets/js/frontend.js?ver=ablocks/assets/css/blocks.style.build.css?ver=ablocks/assets/js/blocks.editor.build.js?ver=ablocks/assets/js/blocks.build.js?ver=ablocks/assets/css/theme-builder/frontend.css?ver=ablocks/assets/js/theme-builder/frontend.js?ver=ablocks/assets/css/blocks.style.css?ver=ablocks/assets/js/blocks.js?ver=ablocks/assets/js/theme-builder/editor.js?ver=ablocks/assets/css/theme-builder/editor.css?ver=HTML / DOM Fingerprints
ablocks-frontend-wrapperABLOCKS_ASSETS_URLABLOCKS_ROOT_URLABLOCKS_ROOT_DIR_PATHABLOCKS_ASSETS_PATH+12 moredata-ablocks-block-optionsablocks_params/wp-json/ablocks/v1/get-blocks