
Anywhere Blocks by Shortcode Security & Risk Analysis
wordpress.org/plugins/anywhere-blocks-shortcodeDisplay Gutenberg blocks using shortcode anywhere on your site. Create reusable block templates and embed them with simple shortcodes.
Is Anywhere Blocks by Shortcode Safe to Use in 2026?
Generally Safe
Score 100/100Anywhere Blocks by Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'anywhere-blocks-shortcode' plugin v1.0.1 demonstrates a strong security posture based on the provided static analysis. The absence of identified dangerous functions, external HTTP requests, file operations, and the use of prepared statements for all SQL queries indicate a conscientious development approach. Furthermore, all identified output is properly escaped, and the plugin appears to have no known vulnerabilities or CVEs, suggesting a history of secure development and maintenance. The total entry points are zero, with none unprotected, which significantly reduces the attack surface. This plugin exhibits excellent adherence to common WordPress security best practices.
However, the complete absence of any identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) is unusual and could indicate either a very simple plugin with no user-facing interactivity or a limitation in the static analysis tool's ability to detect certain types of entry points. While the lack of identified vulnerabilities is positive, the complete lack of nonce and capability checks, even with zero identified entry points, represents a potential weakness. If any entry points were introduced in future versions without proper checks, they could pose a risk. The taint analysis showing zero flows is also noteworthy, but again, might be a reflection of the plugin's simplicity or analysis tool limitations. Overall, the plugin appears very secure in its current state, but the complete lack of common security checks is a minor concern that could be addressed proactively.
Key Concerns
- No nonce checks found
- No capability checks found
Anywhere Blocks by Shortcode Security Vulnerabilities
Anywhere Blocks by Shortcode Release Timeline
Anywhere Blocks by Shortcode Code Analysis
Output Escaping
Anywhere Blocks by Shortcode Attack Surface
WordPress Hooks 3
Maintenance & Trust
Anywhere Blocks by Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Anywhere Blocks by Shortcode Alternatives
List Last Changes
list-last-changes
Shows a list of the last changes of a WordPress site.
Block Editor Templates
block-editor-templates
Templates for the WordPress Block Editor.
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Starter Templates – AI-Powered Templates for Elementor & Gutenberg
astra-sites
The growing library of 300+ ready-to-use templates that work with all WordPress themes including Astra, Hello, OceanWP, GeneratePress and more
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
Anywhere Blocks by Shortcode Developer Profile
14 plugins · 19K total installs
How We Detect Anywhere Blocks by Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/anywhere-blocks-shortcode/build/index.js/wp-content/plugins/anywhere-blocks-shortcode/build/index.js/wp-content/plugins/anywhere-blocks-shortcode/build/index.js?ver=HTML / DOM Fingerprints
[anbsg_block[anbsg_block id=[anbsg_block title=