bcodecraft Blocks Security & Risk Analysis

wordpress.org/plugins/bcodecraft-blocks

A modern WordPress plugin for managing and reusing content snippets with seamless Block Editor integration and advanced search functionality.

0 active installs v1.2.3 PHP 7.4+ WP 6.0+ Updated Sep 13, 2025
blockseditorgutenbergreusable-contentsnippets
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is bcodecraft Blocks Safe to Use in 2026?

Generally Safe

Score 100/100

bcodecraft Blocks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The bcodecraft-blocks plugin version 1.2.3 exhibits a strong security posture based on the provided static analysis and vulnerability history. The plugin demonstrates excellent adherence to security best practices, with all identified entry points (AJAX handlers, REST API routes, and shortcodes) protected by proper authentication and authorization checks. Notably, 100% of output is properly escaped, and SQL queries largely utilize prepared statements (86%), significantly mitigating common injection risks. The absence of any recorded vulnerabilities or CVEs, coupled with zero critical or high severity taint flows, further reinforces its current security.

While the plugin scores highly on security fundamentals, a few minor areas warrant consideration for an even more robust defense. The presence of a file operation and bundled TinyMCE library, while not immediately indicating a vulnerability in this version, are potential attack vectors if not diligently managed and updated in future iterations. The total number of entry points, though protected, does contribute to the overall attack surface. In conclusion, bcodecraft-blocks v1.2.3 is a well-secured plugin with a proactive approach to security, demonstrating strong defensive coding. The lack of historical vulnerabilities is a positive indicator, but ongoing vigilance regarding bundled libraries and potential future attack surface expansion remains prudent.

Key Concerns

  • Bundled library (TinyMCE)
  • File operation present
Vulnerabilities
None known

bcodecraft Blocks Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

bcodecraft Blocks Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
6 prepared
Unescaped Output
0
31 escaped
Nonce Checks
3
Capability Checks
7
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

SQL Query Safety

86% prepared7 total queries

Output Escaping

100% escaped31 total outputs
Attack Surface

bcodecraft Blocks Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 1

authwp_ajax_snippy_blocks_validate_contentincludes\class-snippy-blocks-security.php:17

REST API Routes 2

GET/wp-json/bccb-blocks/v1/snippetsincludes\class-snippy-blocks-rest-api.php:14
GET/wp-json/bccb-blocks/v1/snippets/(?P<id>\d+)includes\class-snippy-blocks-rest-api.php:40

Shortcodes 1

[bccb_block] includes\class-snippy-blocks-shortcode.php:14
WordPress Hooks 19
actioninitincludes\class-snippy-blocks-cpt.php:10
filtermanage_bccb-blocks_posts_columnsincludes\class-snippy-blocks-cpt.php:11
actionmanage_bccb-blocks_posts_custom_columnincludes\class-snippy-blocks-cpt.php:12
actionadmin_enqueue_scriptsincludes\class-snippy-blocks-cpt.php:13
actioninitincludes\class-snippy-blocks-editor.php:10
filterrender_blockincludes\class-snippy-blocks-editor.php:11
filtermce_external_pluginsincludes\class-snippy-blocks-editor.php:12
filtermce_buttonsincludes\class-snippy-blocks-editor.php:13
actionadmin_enqueue_scriptsincludes\class-snippy-blocks-editor.php:14
actionrest_api_initincludes\class-snippy-blocks-rest-api.php:10
actioninitincludes\class-snippy-blocks-security.php:15
filterwp_kses_allowed_htmlincludes\class-snippy-blocks-security.php:16
actionadmin_initincludes\class-snippy-blocks-security.php:18
actionwp_loadedincludes\class-snippy-blocks-security.php:24
actionadmin_headincludes\class-snippy-blocks-security.php:33
actioninitincludes\class-snippy-blocks-shortcode.php:10
actioninitsnippy-blocks.php:35
actionplugins_loadedsnippy-blocks.php:36
actionadmin_noticessnippy-blocks.php:64
Maintenance & Trust

bcodecraft Blocks Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 13, 2025
PHP min version7.4
Downloads279

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

bcodecraft Blocks Developer Profile

BCodeCraft

5 plugins · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect bcodecraft Blocks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bcodecraft-blocks/assets/js/bccb-editor.min.js/wp-content/plugins/bcodecraft-blocks/assets/css/bccb-admin.css/wp-content/plugins/bcodecraft-blocks/assets/js/bccb-admin.min.js/wp-content/plugins/bcodecraft-blocks/assets/css/bccb-editor.css
Script Paths
/wp-content/plugins/bcodecraft-blocks/assets/js/bccb-editor.min.js/wp-content/plugins/bcodecraft-blocks/assets/js/bccb-admin.min.js
Version Parameters
bcodecraft-blocks/assets/css/bccb-editor.css?ver=bcodecraft-blocks/assets/js/bccb-editor.min.js?ver=bcodecraft-blocks/assets/css/bccb-admin.css?ver=bcodecraft-blocks/assets/js/bccb-admin.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
bccb-shortcode-wrapperbccb-shortcode-inputbccb-copy-btnbccb-editor-wrapper
Data Attributes
data-shortcode
JS Globals
bccb_editor_settings
REST Endpoints
/wp-json/bccb-blocks/v1/snippets
Shortcode Output
[bccb id=
FAQ

Frequently Asked Questions about bcodecraft Blocks