
Block Controller Security & Risk Analysis
wordpress.org/plugins/block-controller[Deprecated!] Allow site administrators to control editor access to content blocks.
Is Block Controller Safe to Use in 2026?
Mostly Safe
Score 71/100Block Controller is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.
The 'block-controller' plugin v1.4.3 exhibits a mixed security posture. On the positive side, the plugin has no exposed AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface from common entry points. All SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are excellent security practices. However, a significant concern is the low rate of properly escaped output (6%), indicating a high potential for Cross-Site Scripting (XSS) vulnerabilities, even if none were specifically identified in the static analysis code signals. The single taint flow with unsanitized paths is also a concern, though it did not reach a critical or high severity in this analysis.
The vulnerability history reveals a known medium severity CVE for Improper Neutralization of Input During Web Page Generation (XSS), which is currently unpatched. This past vulnerability, combined with the low output escaping rate, strongly suggests that XSS is a recurring and persistent issue with this plugin. While the plugin has no critical or high severity vulnerabilities detected in the code signals, the combination of poor output escaping and an unpatched XSS vulnerability presents a tangible risk to users. The lack of nonce and capability checks on any potential (though currently zero) entry points is also a weakness that could become exploitable if the attack surface were to expand in future versions.
Key Concerns
- Unpatched medium severity CVE (XSS)
- Low output escaping rate (6%)
- Taint flow with unsanitized paths
- Missing nonce checks (on potential entry points)
- Missing capability checks (on potential entry points)
Block Controller Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Block Controller <= 1.4.3 - Reflected Cross-Site Scripting
Block Controller Release Timeline
Block Controller Code Analysis
Output Escaping
Data Flow Analysis
Block Controller Attack Surface
WordPress Hooks 7
Maintenance & Trust
Block Controller Maintenance & Trust
Maintenance Signals
Community Trust
Block Controller Alternatives
Content Egg – Affiliate Product Importer & Price Comparison
content-egg
Import affiliate products, compare prices, and publish structured product reviews with 25+ editorial Gutenberg blocks — all in one affiliate toolkit.
Table Of Contents Block
table-of-contents-block
Automatically Add Table of Contents Block for your WordPress Posts & Pages
Blocks to Shortcode – Use blocks everywhere: in page templates, Elementor, etc.
blocks-to-shortcode
Easily convert blocks into shortcodes and reuse them anywhere on your site - in posts, pages, widgets, templates, and page builders like Elementor.
Block Permissions
block-permissions
Show Gutenberg editor blocks only to target audience depending on their user attributes such as user role, log in information and user names.
Text Carousel Block
text-carousel-block
Text Carousel Block is a simple plugin that adds a Gutenberg block for inserting Text Content Carousel to your posts and pages.
Block Controller Developer Profile
3 plugins · 50 total installs
How We Detect Block Controller
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/block-controller/build/block-controller.css/wp-content/plugins/block-controller/build/block-controller-admin.min.js/wp-content/plugins/block-controller/build/block-controller-editor.min.js/wp-content/plugins/block-controller/build/block-controller-admin.min.js/wp-content/plugins/block-controller/build/block-controller-editor.min.jsHTML / DOM Fingerprints
TPM_BC_GLOBAL