Advanced Post Block – Showcase Posts with Grid, List, Card Layouts and Filters Security & Risk Analysis

wordpress.org/plugins/advanced-post-block

Advanced Post Block lets you add dynamic post grids, lists, sliders, and tickers. Filter content by category, tag, author, or custom post type.

10K active installs v2.1.0 PHP 7.1+ WP 6.5+ Updated Apr 7, 2026
blockpost-filterpost-gridpost-listpost-slider
100
A · Safe
CVEs total1
Unpatched0
Last CVEApr 11, 2024
Safety Verdict

Is Advanced Post Block – Showcase Posts with Grid, List, Card Layouts and Filters Safe to Use in 2026?

Generally Safe

Score 100/100

Advanced Post Block – Showcase Posts with Grid, List, Card Layouts and Filters has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Apr 11, 2024Updated 1mo ago
Risk Assessment

The "advanced-post-block" plugin v2.0.7 presents a generally good security posture with several strengths. The absence of critical or high-severity taint flows, the use of prepared statements for all SQL queries, and the high percentage of properly escaped output are commendable practices. Furthermore, the plugin boasts a relatively small attack surface with no unprotected entry points identified in the static analysis.

However, a significant concern arises from the plugin's vulnerability history. The presence of a past medium-severity vulnerability, specifically categorized as "Missing Authorization," is a red flag. While there are currently no unpatched CVEs, this history suggests a recurring weakness that, if not adequately addressed, could resurface. The limited number of nonce and capability checks (2 each) also warrants attention, as a more robust implementation could further harden the plugin against potential attacks, especially given the attack surface.

In conclusion, while the current version of "advanced-post-block" demonstrates a commitment to secure coding practices in several key areas, the historical vulnerability concerning missing authorization indicates a potential area for improvement. Developers should ensure that all entry points, even those without immediate authorization checks in static analysis, are rigorously secured, and review the implementation of nonce and capability checks to bolster the plugin's overall resilience.

Key Concerns

  • Past medium vulnerability: Missing Authorization
  • Limited Nonce checks (2)
  • Limited Capability checks (2)
Vulnerabilities
1 published

Advanced Post Block – Showcase Posts with Grid, List, Card Layouts and Filters Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-0908medium · 5.3Missing Authorization

Advanced Post Block – Display Posts, Pages, or Custom Posts on Your Page <= 1.13.4 - Missing Authorization to Information Disclosure

Apr 11, 2024 Patched in 1.13.5 (29d)
Version History

Advanced Post Block – Showcase Posts with Grid, List, Card Layouts and Filters Release Timeline

v2.1.0Current
v2.0.8
v2.0.7
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v2.0.0
v1.16.1
v1.16.0
v1.15.4
v1.15.3
v1.15.2
v1.15.1
v1.15.0
v1.14.9
v1.14.8
v1.14.7
Code Analysis
Analyzed Mar 16, 2026

Advanced Post Block – Showcase Posts with Grid, List, Card Layouts and Filters Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
36 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius

Output Escaping

88% escaped41 total outputs
Attack Surface

Advanced Post Block – Showcase Posts with Grid, List, Card Layouts and Filters Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 4

authwp_ajax_apbPostsincludes\Ajax.php:8
noprivwp_ajax_apbPostsincludes\Ajax.php:9
authwp_ajax_apb_post_viewincludes\Tracker.php:9
noprivwp_ajax_apb_post_viewincludes\Tracker.php:10

Shortcodes 1

[apb] includes\admin\CPT.php:13
WordPress Hooks 15
actionadmin_menuincludes\admin\CPT.php:10
actionadmin_enqueue_scriptsincludes\admin\CPT.php:11
actioninitincludes\admin\CPT.php:12
filtermanage_apb_posts_columnsincludes\admin\CPT.php:14
actionmanage_apb_posts_custom_columnincludes\admin\CPT.php:15
actionuse_block_editor_for_postincludes\admin\CPT.php:16
filterapb_excerpt_filterincludes\Posts.php:10
actionwp_headincludes\Tracker.php:8
filterplugin_row_metaplugin.php:44
actioninitplugin.php:45
filterblock_categories_allplugin.php:46
actionadmin_enqueue_scriptsplugin.php:47
actionenqueue_block_editor_assetsplugin.php:48
actionenqueue_block_assetsplugin.php:49
filterplugin_action_linksplugin.php:51
Maintenance & Trust

Advanced Post Block – Showcase Posts with Grid, List, Card Layouts and Filters Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 7, 2026
PHP min version7.1
Downloads548K

Community Trust

Rating84/100
Number of ratings17
Active installs10K
Developer Profile

Advanced Post Block – Showcase Posts with Grid, List, Card Layouts and Filters Developer Profile

colorlibplugins

121 plugins · 740K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
130 days
View full developer profile
Detection Fingerprints

How We Detect Advanced Post Block – Showcase Posts with Grid, List, Card Layouts and Filters

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-post-block/build/admin/dashboard.css/wp-content/plugins/advanced-post-block/build/admin/post.css/wp-content/plugins/advanced-post-block/build/admin/dashboard.js/wp-content/plugins/advanced-post-block/build/admin/post.js/wp-content/plugins/advanced-post-block/public/js/easy-ticker.min.js
Script Paths
/wp-content/plugins/advanced-post-block/build/admin/dashboard.js/wp-content/plugins/advanced-post-block/build/admin/post.js/wp-content/plugins/advanced-post-block/public/js/easy-ticker.min.js
Version Parameters
advanced-post-block/build/admin/dashboard.css?ver=advanced-post-block/build/admin/post.css?ver=advanced-post-block/build/admin/dashboard.js?ver=advanced-post-block/build/admin/post.js?ver=advanced-post-block/public/js/easy-ticker.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
apbDashboard
Data Attributes
data-info
JS Globals
apbpipecheckapbpricingurl
Shortcode Output
[apb]
FAQ

Frequently Asked Questions about Advanced Post Block – Showcase Posts with Grid, List, Card Layouts and Filters