Advanced Button Block Security & Risk Analysis

wordpress.org/plugins/advanced-button-block

Lets you add a fully customizable button block in Gutenberg editor.

10 active installs v1.0.2 PHP + WP 4.2+ Updated Unknown
animationsbuttoncontentconversionsgutenberg
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Advanced Button Block Safe to Use in 2026?

Generally Safe

Score 100/100

Advanced Button Block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "advanced-button-block" plugin v1.0.2 demonstrates a strong security posture based on the provided static analysis. The absence of any dangerous functions, SQL queries that are not properly prepared, and fully escaped output are all positive indicators. Furthermore, the lack of file operations and external HTTP requests limits potential attack vectors. The plugin also shows no history of known vulnerabilities, which is a very good sign for its stability and security.

However, the analysis does highlight a significant lack of security checks. There are no AJAX handlers, REST API routes, shortcodes, or cron events, which means there are no entry points to analyze for potential vulnerabilities. Crucially, the absence of nonce checks and capability checks is a major concern. While the current version may not have exploitable entry points, if any are introduced in future versions without these crucial security measures, they could be easily exploited. This lack of built-in authentication and authorization mechanisms presents a latent risk.

In conclusion, the plugin is commendably built with secure coding practices regarding SQL and output handling. The clean vulnerability history further reinforces its apparent security. Nevertheless, the complete absence of authentication and authorization checks for any potential entry points is a critical weakness. While there are no current vulnerabilities stemming from this, it creates a precarious situation for future development and makes the plugin reliant on external factors for security. This plugin is currently safe due to its lack of features, but has a high potential for future vulnerabilities if features are added without proper security controls.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Advanced Button Block Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Advanced Button Block Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Advanced Button Block Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionenqueue_block_assetssrc\init.php:34
actionenqueue_block_editor_assetssrc\init.php:66
Maintenance & Trust

Advanced Button Block Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating74/100
Number of ratings3
Active installs10
Developer Profile

Advanced Button Block Developer Profile

poglaa

3 plugins · 110 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Advanced Button Block

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-button-block/dist/blocks.style.build.css/wp-content/plugins/advanced-button-block/dist/blocks.build.js/wp-content/plugins/advanced-button-block/dist/blocks.editor.build.css
Script Paths
/wp-content/plugins/advanced-button-block/dist/blocks.build.js

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Advanced Button Block