
Gutenberg Blocks – ACF Blocks Suite Security & Risk Analysis
wordpress.org/plugins/acf-blocksSupercharge your Gutenberg editor with high-quality creative Gutenberg Blocks. Ready-to-use ACF Blocks!
Is Gutenberg Blocks – ACF Blocks Suite Safe to Use in 2026?
Mostly Safe
Score 70/100Gutenberg Blocks – ACF Blocks Suite is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.
The 'acf-blocks' plugin v2.6.11 exhibits a mixed security posture. On the positive side, the static analysis reveals a notably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication. Furthermore, all SQL queries are properly prepared, indicating good database interaction practices. However, a significant concern arises from the low percentage of properly escaped output (13%), suggesting a high potential for Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's historical vulnerability types. The absence of nonce and capability checks on entry points, while currently not directly exploitable due to the limited attack surface, represents a missed security control that could become problematic if new entry points are introduced without proper validation. The plugin's vulnerability history includes a medium severity CVE related to XSS, which is currently unpatched. This pattern, combined with the output escaping issues, points to a recurring weakness in sanitizing user-provided data before it's displayed, posing a tangible risk to users. While the plugin has strengths in its limited attack surface and secure SQL handling, the prevalent output escaping deficiency and the presence of an unpatched XSS vulnerability demand immediate attention.
Key Concerns
- Unpatched CVE (medium severity)
- Low output escaping rate (13%)
- No nonce checks
- No capability checks
- Bundled outdated library (Freemius v1.0)
Gutenberg Blocks – ACF Blocks Suite Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Gutenberg Blocks – ACF Blocks Suite <= 2.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
Gutenberg Blocks – ACF Blocks Suite Release Timeline
Gutenberg Blocks – ACF Blocks Suite Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Gutenberg Blocks – ACF Blocks Suite Attack Surface
WordPress Hooks 23
Maintenance & Trust
Gutenberg Blocks – ACF Blocks Suite Maintenance & Trust
Maintenance Signals
Community Trust
Gutenberg Blocks – ACF Blocks Suite Alternatives
Virtual Window Custom Blocks
virtualwindow-custom-blocks
Boost Your WordPress Website with Virtual Window Custom Blocks
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Page Builder Gutenberg Blocks – CoBlocks
coblocks
CoBlocks is a suite of page builder WordPress blocks for Gutenberg, with 10+ new blocks and a true page builder experience with rows and columns.
Gutenberg Blocks – ACF Blocks Suite Developer Profile
16 plugins · 3.5M total installs
How We Detect Gutenberg Blocks – ACF Blocks Suite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acf-blocks/free-acf-blocks.php/wp-content/plugins/acf-blocks/pro-acf-blocks.php/wp-content/plugins/acf-blocks/img/gtwo-one.png/wp-content/plugins/acf-blocks/img/gtwo-two.png/wp-content/plugins/acf-blocks/img/gthree-one.png/wp-content/plugins/acf-blocks/img/gthree-two.png/wp-content/plugins/acf-blocks/img/gthree-three.png/wp-content/plugins/acf-blocks/img/gthree-four.png+1 moreHTML / DOM Fingerprints
acf-block-librarydata-acf-block-typedata-acf-block-previewacfBlocksConfig