
Alert Box Block – Display Custom Alerts and Messages Security & Risk Analysis
wordpress.org/plugins/alert-box-blockDisplay notices/alerts on the page.
Is Alert Box Block – Display Custom Alerts and Messages Safe to Use in 2026?
Generally Safe
Score 99/100Alert Box Block – Display Custom Alerts and Messages has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The alert-box-block plugin version 2.0.0 demonstrates a generally strong security posture based on the static analysis. The absence of any detected dangerous functions, unsanitized taint flows, raw SQL queries, file operations, or external HTTP requests is commendable. The presence of nonce and capability checks, along with proper output escaping for all detected outputs, indicates adherence to good WordPress security practices. However, the plugin's vulnerability history is a significant concern. With two previously disclosed medium-severity cross-site scripting (XSS) vulnerabilities, the plugin has a documented track record of security flaws. The fact that the last vulnerability was in March 2025, and is listed as 'currently unpatched' (though this might be an anomaly in the data, as there are 0 currently unpatched CVEs), warrants careful consideration. This history suggests that while the current version might be cleaner, past issues might indicate underlying development practices that could lead to future vulnerabilities.
Key Concerns
- Two documented medium severity CVEs
- Bundled Freemius library
Alert Box Block – Display Custom Alerts and Messages Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Alert Box Block – Display notice/alerts in the front end <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Alert Box Block
Alert Box Block – Display notice/alerts in the front end <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Alert Box Block – Display Custom Alerts and Messages Release Timeline
Alert Box Block – Display Custom Alerts and Messages Code Analysis
Bundled Libraries
Output Escaping
Alert Box Block – Display Custom Alerts and Messages Attack Surface
WordPress Hooks 7
Maintenance & Trust
Alert Box Block – Display Custom Alerts and Messages Maintenance & Trust
Maintenance Signals
Community Trust
Alert Box Block – Display Custom Alerts and Messages Alternatives
Notice Block
notice-block
Put Spotlight On News, Announcements & Let The Visitors Find It Easily
Gosign – Notification And Alert Block
gosign-notification-and-alert-block
Plugin contains the options to set notification or alert blocks. It offors multiple options to customise the block i.e headlines fonts, sizes, colors, …
Alerts DLX – Alert Box, Callout Box, and Notifications
alerts-dlx
Add beautiful tips, warnings, notes, and callout boxes to your WordPress posts and pages in seconds.
Alertify Blocks – Advanced Notification Blocks
alertify-blocks
A collection of beautiful alert/notice blocks for the WordPress block editor.
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Alert Box Block – Display Custom Alerts and Messages Developer Profile
121 plugins · 740K total installs
How We Detect Alert Box Block – Display Custom Alerts and Messages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/alert-box-block/public/css/font-awesome.min.css/wp-content/plugins/alert-box-block/build/admin-dashboard.css/wp-content/plugins/alert-box-block/build/admin-dashboard.jsalert-box-block/build/admin-dashboard.js?ver=alert-box-block/build/admin-dashboard.css?ver=HTML / DOM Fingerprints
data-infoabbpipecheck