
BetterBlocks Security & Risk Analysis
wordpress.org/plugins/betterblocksHandy improvements for the Wordpress block editor interface such as post type support, hiding blocks, adjustable sidebar, and more.
Is BetterBlocks Safe to Use in 2026?
Generally Safe
Score 100/100BetterBlocks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "betterblocks" v1.0.17 plugin exhibits a generally strong security posture based on the provided static analysis. There are no identified vulnerabilities in its history, and the code analysis reveals no dangerous functions, file operations, external HTTP requests, or SQL queries that are not properly prepared. The absence of any taint flow analysis results further suggests a lack of immediately apparent vulnerabilities in data handling.
However, a significant concern arises from the output escaping. With only 33% of the 18 identified outputs being properly escaped, there is a substantial risk of cross-site scripting (XSS) vulnerabilities. If user-supplied data is not adequately sanitized before being displayed, an attacker could inject malicious scripts. While the attack surface appears minimal and protected, the lack of nonce checks is also a weakness, especially if any of the protected entry points were to be extended in future versions without proper security considerations.
Overall, the plugin demonstrates good practices in areas like SQL querying and avoiding dangerous functions. The lack of historical vulnerabilities is a positive indicator. Nevertheless, the significant percentage of unescaped output presents a clear and present danger that requires immediate attention. Addressing this output escaping issue should be the top priority to improve the plugin's security.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks found
BetterBlocks Security Vulnerabilities
BetterBlocks Code Analysis
Output Escaping
BetterBlocks Attack Surface
WordPress Hooks 8
Maintenance & Trust
BetterBlocks Maintenance & Trust
Maintenance Signals
Community Trust
BetterBlocks Alternatives
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Starter Templates – AI-Powered Templates for Elementor & Gutenberg
astra-sites
The growing library of 300+ ready-to-use templates that work with all WordPress themes including Astra, Hello, OceanWP, GeneratePress and more
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
Disable Gutenberg
disable-gutenberg
Disable Gutenberg Block Editor and restore the Classic Editor and original Edit Post screen (TinyMCE, meta boxes, etc.).
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns
essential-blocks
Gutenberg block editor with AI. 70+ Gutenberg blocks, patterns, WooCommerce blocks, post grid, gallery, menu with Gutenberg block library.
BetterBlocks Developer Profile
7 plugins · 12K total installs
How We Detect BetterBlocks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/betterblocks/css/betterblocks-admin.css/wp-content/plugins/betterblocks/js/betterblocks-admin.js/wp-content/plugins/betterblocks/js/betterblocks-admin.jsbetterblocks-admin.js?ver=betterblocks-admin.css?ver=HTML / DOM Fingerprints
wrapname="betterblocks_post_types[]"name="betterblocks_remove_directory"name="betterblocks_force_preview"