
Block Controller Security & Risk Analysis
wordpress.org/plugins/block-controller[Deprecated!] Allow site administrators to control editor access to content blocks.
Is Block Controller Safe to Use in 2026?
Mostly Safe
Score 79/100Block Controller is generally safe to use. 1 past CVE were resolved. Keep it updated.
The 'block-controller' plugin v1.4.3 exhibits a mixed security posture. On the positive side, the plugin has no exposed AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface from common entry points. All SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are excellent security practices. However, a significant concern is the low rate of properly escaped output (6%), indicating a high potential for Cross-Site Scripting (XSS) vulnerabilities, even if none were specifically identified in the static analysis code signals. The single taint flow with unsanitized paths is also a concern, though it did not reach a critical or high severity in this analysis.
The vulnerability history reveals a known medium severity CVE for Improper Neutralization of Input During Web Page Generation (XSS), which is currently unpatched. This past vulnerability, combined with the low output escaping rate, strongly suggests that XSS is a recurring and persistent issue with this plugin. While the plugin has no critical or high severity vulnerabilities detected in the code signals, the combination of poor output escaping and an unpatched XSS vulnerability presents a tangible risk to users. The lack of nonce and capability checks on any potential (though currently zero) entry points is also a weakness that could become exploitable if the attack surface were to expand in future versions.
Key Concerns
- Unpatched medium severity CVE (XSS)
- Low output escaping rate (6%)
- Taint flow with unsanitized paths
- Missing nonce checks (on potential entry points)
- Missing capability checks (on potential entry points)
Block Controller Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Block Controller <= 1.4.3 - Reflected Cross-Site Scripting
Block Controller Code Analysis
Output Escaping
Data Flow Analysis
Block Controller Attack Surface
WordPress Hooks 7
Maintenance & Trust
Block Controller Maintenance & Trust
Maintenance Signals
Community Trust
Block Controller Alternatives
Table Of Contents Block
table-of-contents-block
Automatically Add Table of Contents Block for your WordPress Posts & Pages
ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns
zoloblocks
Empowering Gutenberg block editor to help you create WordPress websites with 55+ free Advanced blocks, 300+ patterns, 100+ ready pages and more.
Blocks
blocks
Simple and flexible content management block with a [shortcode]. This can be used for reusable text or widgets.
Block Permissions
block-permissions
Show Gutenberg editor blocks only to target audience depending on their user attributes such as user role, log in information and user names.
Blocks to Shortcode – Use blocks everywhere: in page templates, Elementor, etc.
blocks-to-shortcode
Easily convert blocks into shortcodes and reuse them anywhere on your site - in posts, pages, widgets, templates, and page builders like Elementor.
Block Controller Developer Profile
3 plugins · 50 total installs
How We Detect Block Controller
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/block-controller/build/block-controller.css/wp-content/plugins/block-controller/build/block-controller-admin.min.js/wp-content/plugins/block-controller/build/block-controller-editor.min.js/wp-content/plugins/block-controller/build/block-controller-admin.min.js/wp-content/plugins/block-controller/build/block-controller-editor.min.jsHTML / DOM Fingerprints
TPM_BC_GLOBAL