
Block Catalog Security & Risk Analysis
wordpress.org/plugins/block-catalogKeep track of which Gutenberg Blocks are used across your site.
Is Block Catalog Safe to Use in 2026?
Generally Safe
Score 100/100Block Catalog has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "block-catalog" plugin version 1.6.2 demonstrates a strong security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the consistent application of output escaping are significant strengths. Furthermore, the presence of capability checks on all identified REST API routes and the lack of critical or high severity taint flows indicate a diligent approach to secure coding practices. The plugin also has no recorded vulnerabilities, which is a very positive indicator of its historical security.
Despite the overwhelmingly positive analysis, a notable area for improvement is the absence of nonce checks. While all REST API routes have capability checks, nonce checks are a crucial defense against Cross-Site Request Forgery (CSRF) attacks, especially for actions that modify data. Their absence represents a potential, albeit currently undocumented, weakness in the plugin's attack surface.
In conclusion, "block-catalog" v1.6.2 appears to be a securely developed plugin with excellent practices in place regarding data handling and output. The primary concern is the lack of nonce checks, which is a standard security measure for certain types of operations. The vulnerability history is clean, suggesting a commitment to security. Overall, the risk associated with this plugin is low, but the implementation of nonce checks would further solidify its security.
Key Concerns
- Missing nonce checks
Block Catalog Security Vulnerabilities
Block Catalog Code Analysis
SQL Query Safety
Output Escaping
Block Catalog Attack Surface
REST API Routes 4
WordPress Hooks 12
Maintenance & Trust
Block Catalog Maintenance & Trust
Maintenance Signals
Community Trust
Block Catalog Alternatives
Blockenberg — 600+ Advanced Gutenberg Blocks for WordPress Block Editor
blockenberg
600+ Gutenberg blocks for layouts, content, media, marketing, charts, calculators, testimonials, tables, maps, videos and more.
Block Designer – Create Custom Blocks for Gutenberg Editor
block-designer
Create and design custom blocks for the WordPress Gutenberg Block Editor without any line of code.
Embed Block for Figma
embed-block-figma
Display Figma files using an Embed block.
Wicked Block Builder
wicked-block-builder
Create your own custom blocks and patterns in as little as a few minutes!
Caledros Basic Blocks
caledros-basic-blocks
Introduces 18 lightweight blocks for the Gutenberg editor. Also includes an optional preloader for CSS stylesheets to enhance performance.
Block Catalog Developer Profile
23 plugins · 1.4M total installs
How We Detect Block Catalog
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/block-catalog/dist/tools.js/wp-content/plugins/block-catalog/dist/styles.css/wp-content/plugins/block-catalog/dist/admin-scripts.js/wp-content/plugins/block-catalog/dist/admin-styles.css/wp-content/plugins/block-catalog/dist/tools.js/wp-content/plugins/block-catalog/dist/admin-scripts.jsblock-catalog/dist/tools.js?ver=block-catalog/dist/styles.css?ver=block-catalog/dist/admin-scripts.js?ver=block-catalog/dist/admin-styles.css?ver=HTML / DOM Fingerprints
block-catalog-post-typedata-block-catalog-index-urldata-block-catalog-delete-index-urlblock_catalog/wp-json/block-catalog/v1/posts/wp-json/block-catalog/v1/index/wp-json/block-catalog/v1/terms/wp-json/block-catalog/v1/delete-index