Alert Box Block – Display Custom Alerts and Messages Security & Risk Analysis

wordpress.org/plugins/alert-box-block

Display notices/alerts on the page.

500 active installs v2.0.0 PHP 7.1+ WP 6.5+ Updated Mar 28, 2026
alertalert-boxalert-box-blockblockgutenberg-block
99
A · Safe
CVEs total2
Unpatched0
Last CVEMar 24, 2025
Download
Safety Verdict

Is Alert Box Block – Display Custom Alerts and Messages Safe to Use in 2026?

Generally Safe

Score 99/100

Alert Box Block – Display Custom Alerts and Messages has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Mar 24, 2025Updated 1mo ago
Risk Assessment

The alert-box-block plugin version 2.0.0 demonstrates a generally strong security posture based on the static analysis. The absence of any detected dangerous functions, unsanitized taint flows, raw SQL queries, file operations, or external HTTP requests is commendable. The presence of nonce and capability checks, along with proper output escaping for all detected outputs, indicates adherence to good WordPress security practices. However, the plugin's vulnerability history is a significant concern. With two previously disclosed medium-severity cross-site scripting (XSS) vulnerabilities, the plugin has a documented track record of security flaws. The fact that the last vulnerability was in March 2025, and is listed as 'currently unpatched' (though this might be an anomaly in the data, as there are 0 currently unpatched CVEs), warrants careful consideration. This history suggests that while the current version might be cleaner, past issues might indicate underlying development practices that could lead to future vulnerabilities.

Key Concerns

  • Two documented medium severity CVEs
  • Bundled Freemius library
Vulnerabilities
2 published

Alert Box Block – Display Custom Alerts and Messages Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-13731medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Alert Box Block – Display notice/alerts in the front end <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Alert Box Block

Mar 24, 2025 Patched in 1.1.4 (46d)
CVE-2025-22675medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Alert Box Block – Display notice/alerts in the front end <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Feb 3, 2025 Patched in 1.1.1 (10d)
Version History

Alert Box Block – Display Custom Alerts and Messages Release Timeline

Code Analysis
Analyzed Mar 16, 2026

Alert Box Block – Display Custom Alerts and Messages Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius

Output Escaping

100% escaped5 total outputs
Attack Surface

Alert Box Block – Display Custom Alerts and Messages Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menuincludes\Menu.php:7
actionadmin_enqueue_scriptsincludes\Menu.php:8
actioninitplugin.php:48
actionenqueue_block_assetsplugin.php:49
actionenqueue_block_editor_assetsplugin.php:50
filterdefault_titleplugin.php:51
filterdefault_contentplugin.php:52
Maintenance & Trust

Alert Box Block – Display Custom Alerts and Messages Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 28, 2026
PHP min version7.1
Downloads11K

Community Trust

Rating100/100
Number of ratings1
Active installs500
Developer Profile

Alert Box Block – Display Custom Alerts and Messages Developer Profile

colorlibplugins

121 plugins · 740K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
130 days
View full developer profile
Detection Fingerprints

How We Detect Alert Box Block – Display Custom Alerts and Messages

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/alert-box-block/public/css/font-awesome.min.css/wp-content/plugins/alert-box-block/build/admin-dashboard.css/wp-content/plugins/alert-box-block/build/admin-dashboard.js
Version Parameters
alert-box-block/build/admin-dashboard.js?ver=alert-box-block/build/admin-dashboard.css?ver=

HTML / DOM Fingerprints

Data Attributes
data-info
JS Globals
abbpipecheck
FAQ

Frequently Asked Questions about Alert Box Block – Display Custom Alerts and Messages