Carbon Code Security & Risk Analysis

wordpress.org/plugins/block-carbon-code

Adds the beautiful code editor from carbon.now.sh to the block editor.

10 active installs v1.0.0 PHP 5.6.20+ WP 5.2+ Updated Unknown
blockblock-editorcodegutenberg
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Carbon Code Safe to Use in 2026?

Generally Safe

Score 100/100

Carbon Code has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The block-carbon-code plugin v1.0.0 demonstrates a very strong initial security posture based on the static analysis. The absence of any identified dangerous functions, SQL queries without prepared statements, unescaped output, file operations, external HTTP requests, or any form of taint flow is highly commendable. Furthermore, the lack of AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. The plugin also shows no record of past vulnerabilities, further reinforcing its apparent security. This indicates diligent coding practices and a focus on secure development from the outset. However, the complete absence of any nonce checks or capability checks, while not leading to immediate critical risks in this analysis due to the limited attack surface, represents a potential weakness. If functionality were to be added in the future, these checks would be essential to prevent unauthorized actions or cross-site request forgery. Overall, the plugin is exceptionally secure in its current form, but future development should prioritize implementing these standard WordPress security mechanisms.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Carbon Code Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Carbon Code Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Carbon Code Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Carbon Code Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitsrc\init.php:19
Maintenance & Trust

Carbon Code Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedUnknown
PHP min version5.6.20
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Carbon Code Developer Profile

epiqueras

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Carbon Code

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/block-carbon-code/build/index.asset.php/wp-content/plugins/block-carbon-code/build/index.js/wp-content/plugins/block-carbon-code/build/style-index.css
Script Paths
/wp-content/plugins/block-carbon-code/build/index.js
Version Parameters
/wp-content/plugins/block-carbon-code/build/index.js?ver=/wp-content/plugins/block-carbon-code/build/style-index.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Carbon Code