
Block Editor Bootstrap Blocks Security & Risk Analysis
wordpress.org/plugins/block-editor-bootstrap-blocksFully responsive Bootstrap 5 blocks, components and extends for Gutenberg
Is Block Editor Bootstrap Blocks Safe to Use in 2026?
Generally Safe
Score 99/100Block Editor Bootstrap Blocks has a strong security track record. Known vulnerabilities have been patched promptly.
The "block-editor-bootstrap-blocks" plugin version 6.9.2 exhibits a generally good security posture with several positive indicators. The attack surface is minimal, with only one AJAX handler that appears to be protected by authentication checks. The code also demonstrates a strong commitment to security by exclusively using prepared statements for all SQL queries and implementing nonce checks. A significant majority of output operations are properly escaped, mitigating common cross-site scripting risks. The absence of taint analysis findings for critical or high severity issues further reinforces this positive outlook.
However, there are a few areas that warrant attention. The presence of a past medium severity vulnerability related to cross-site scripting, even though currently unpatched, suggests a potential recurring weakness in input sanitization or output escaping. Furthermore, while the percentage of properly escaped outputs is high at 72%, the remaining 28% represents a potential risk for unpatched or newly discovered XSS vulnerabilities. The lack of capability checks on the AJAX handler, although protected by authentication, is a minor concern that could be improved by enforcing specific user roles or permissions for certain actions.
In conclusion, "block-editor-bootstrap-blocks" v6.9.2 is a relatively secure plugin with robust SQL handling and good general output escaping. The small attack surface and use of nonces are commendable. The primary areas for improvement lie in ensuring 100% output escaping and potentially adding capability checks to the existing AJAX handler to further harden its security. The history of a past XSS vulnerability, while patched, should serve as a reminder to maintain vigilance in code reviews.
Key Concerns
- Past medium severity XSS vulnerability
- 28% of outputs unescaped
- Missing capability checks on AJAX handler
Block Editor Bootstrap Blocks Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Block Editor Bootstrap Blocks <= 6.6.1 - Reflected Cross-Site Scripting via tab
Block Editor Bootstrap Blocks Code Analysis
Output Escaping
Block Editor Bootstrap Blocks Attack Surface
AJAX Handlers 1
WordPress Hooks 19
Maintenance & Trust
Block Editor Bootstrap Blocks Maintenance & Trust
Maintenance Signals
Community Trust
Block Editor Bootstrap Blocks Alternatives
Advanced Columns Block: Layout builder
advanced-columns-block
The professional plugin for creating responsive layouts in WordPress.
PixGridder
pixgridder
A simple page grid composer that splits your pages into ordered grids, a builder for rows and columns
Columns Reordering For Elementor
columns-reordering-for-elementor
This plugin adds "Display Order" control to help you easily reorder Elementor columns, sections and widgets responsively. No need to duplicate things!
Featured Post Creative
featured-post-creative
Display Featured post on your website with 2 shortcode and 1 widget. Also work with Gutenberg shortcode block.
WEN Responsive Columns
wen-responsive-columns
Easily display columnized content in your pages or posts.
Block Editor Bootstrap Blocks Developer Profile
13 plugins · 136K total installs
How We Detect Block Editor Bootstrap Blocks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/block-editor-bootstrap-blocks/dist/style.css/wp-content/plugins/block-editor-bootstrap-blocks/dist/blocks.style.css/wp-content/plugins/block-editor-bootstrap-blocks/dist/blocks.editor.css/wp-content/plugins/block-editor-bootstrap-blocks/dist/runtime.js/wp-content/plugins/block-editor-bootstrap-blocks/dist/dependencies.js/wp-content/plugins/block-editor-bootstrap-blocks/dist/index.jsblock-editor-bootstrap-blocks/dist/style.css?ver=block-editor-bootstrap-blocks/dist/blocks.style.css?ver=block-editor-bootstrap-blocks/dist/blocks.editor.css?ver=block-editor-bootstrap-blocks/dist/runtime.js?ver=block-editor-bootstrap-blocks/dist/dependencies.js?ver=block-editor-bootstrap-blocks/dist/index.js?ver=HTML / DOM Fingerprints
bootstrap-noticenotice-altnotice-largenotice-successbs-offset-helperis-dismissibledata-bs-toggledata-bs-targetdata-bs-dismissdata-bs-placementdata-bs-triggerdata-bs-content+1 morebootstrapBlocks