
Block Collections Security & Risk Analysis
wordpress.org/plugins/block-collectionsIt is a plug-in that collects small scale blocks.
Is Block Collections Safe to Use in 2026?
Generally Safe
Score 100/100Block Collections has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the 'block-collections' plugin v1.7.2 reveals a mixed security posture. On the positive side, the code demonstrates good practices by not utilizing dangerous functions, all SQL queries are prepared, and output escaping is consistently applied. There are no observed file operations or external HTTP requests, and importantly, no recorded historical vulnerabilities (CVEs) for this plugin. This indicates a generally robust development approach.
However, a significant concern arises from the identified attack surface. The plugin exposes one REST API route without any permission callbacks. This means that unauthenticated users could potentially interact with this route, presenting a direct security risk. While taint analysis shows no critical or high severity flows, the unprotected REST API route remains a notable weakness that could be exploited if it handles user-supplied data or performs sensitive actions.
In conclusion, while the 'block-collections' plugin benefits from secure coding practices in many areas and a clean vulnerability history, the presence of an unprotected REST API route is a critical oversight. This single entry point without authorization is the primary security concern and warrants immediate attention to mitigate potential risks.
Key Concerns
- Unprotected REST API route
Block Collections Security Vulnerabilities
Block Collections Code Analysis
Block Collections Attack Surface
REST API Routes 1
WordPress Hooks 4
Maintenance & Trust
Block Collections Maintenance & Trust
Maintenance Signals
Community Trust
Block Collections Alternatives
Elementor Blocks for Gutenberg
block-builder
Elementor Blocks for Gutenberg, officially created by Elementor Page Builder, allows you to easily insert any Elementor template into Gutenberg.
Material Design for WordPress
material-design
The official Material Design plugin for WordPress. Customize your site’s navigation, colors, typography, and shapes, use Material Components, and choo …
Visibility Controls for Editor Blocks
visibility-controls-for-editor-blocks
Easily hide or show Gutenberg blocks on mobile, tablet, and desktop devices using customizable breakpoints for responsive design.
Block Designer – Create Custom Blocks for Gutenberg Editor
block-designer
Create and design custom blocks for the WordPress Gutenberg Block Editor without any line of code.
Designer Blocks for Block Editor by Weaver
blocks-by-weaver
Discover the power of the Block Editor! This plugin adds Designer Blocks that make it easy to add Images, Text, and Parallax.
Block Collections Developer Profile
9 plugins · 50 total installs
How We Detect Block Collections
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/block-collections/code-prettify/prettify.js/wp-content/plugins/block-collections/code-prettify/lang-css.js/wp-content/plugins/block-collections/code-prettify/prettify.css/wp-content/plugins/block-collections/build/gutenberg-ex.js/wp-content/plugins/block-collections/code-prettify/init-prettify.js/wp-content/plugins/block-collections/build/block_collection.js/wp-content/plugins/block-collections/assets/css/fontawesome.css/wp-content/plugins/block-collections/assets/css/brands.css+1 more/wp-content/plugins/block-collections/code-prettify/prettify.js/wp-content/plugins/block-collections/code-prettify/lang-css.js/wp-content/plugins/block-collections/build/gutenberg-ex.js/wp-content/plugins/block-collections/code-prettify/init-prettify.js/wp-content/plugins/block-collections/build/block_collection.jsblock-collections/code-prettify/prettify.js?ver=block-collections/code-prettify/lang-css.js?ver=block-collections/code-prettify/prettify.css?ver=block-collections/build/gutenberg-ex.js?ver=block-collections/code-prettify/init-prettify.js?ver=block-collections/build/block_collection.js?ver=block-collections/assets/css/fontawesome.css?ver=6.5.0block-collections/assets/css/brands.css?ver=6.5.0block-collections/assets/css/solid.css?ver=6.5.0HTML / DOM Fingerprints
itmar_block_option/wp-json/itmar/v1/current-user