Block Editor Disabler Security & Risk Analysis

wordpress.org/plugins/block-editor-disabler

This plugin for disable gutenberg editor for specific role.

0 active installs v1.0.2 PHP + WP 6.7+ Updated Jan 13, 2025
block-editorblocksclassic-editorgutenberg
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Block Editor Disabler Safe to Use in 2026?

Generally Safe

Score 92/100

Block Editor Disabler has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The block-editor-disabler plugin exhibits a generally good security posture based on the provided static analysis. The absence of any detected dangerous functions, SQL queries without prepared statements, file operations, or external HTTP requests is a strong indicator of secure coding practices. Furthermore, the high percentage of properly escaped output (98%) minimizes the risk of cross-site scripting (XSS) vulnerabilities. The plugin also has a clean vulnerability history with no recorded CVEs, which suggests a history of stable and secure development.

However, the analysis does reveal a significant concern regarding the complete lack of any capability checks or nonce checks across all entry points. While the attack surface is currently reported as zero, this absence of any authorization or security token verification is a notable weakness. If any new entry points were to be introduced in future versions, or if the current analysis missed any subtle ways to interact with the plugin, the lack of these fundamental security mechanisms would leave them completely unprotected. The taint analysis showing zero flows, while positive, might be influenced by the limited attack surface and lack of identifiable data flows, rather than a guarantee of absolute safety if the attack surface were to expand.

In conclusion, the block-editor-disabler plugin demonstrates good coding hygiene in its current implementation, with no immediate critical vulnerabilities apparent. The primary weakness lies in the absence of essential security checks like capability and nonce verification. This lack of foundational security measures represents a potential risk, especially if the plugin's functionality or interaction points evolve in the future. The clean vulnerability history is a positive sign, but it does not negate the need for robust security checks.

Key Concerns

  • Missing Nonce Checks
  • Missing Capability Checks
Vulnerabilities
None known

Block Editor Disabler Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Block Editor Disabler Release Timeline

v1.0.2Current
v1.0.1
Code Analysis
Analyzed Apr 16, 2026

Block Editor Disabler Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
40 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped41 total outputs
Attack Surface

Block Editor Disabler Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
filteruse_block_editor_for_post_typeincludes/class-hooks.php:18
filteruse_block_editor_for_postincludes/class-hooks.php:19
filteruse_block_editor_for_postincludes/class-hooks.php:20
filteruse_block_editor_for_post_typeincludes/class-hooks.php:21
actionadmin_menuincludes/class-settings.php:18
actionadmin_initincludes/class-settings.php:19
filterplugin_action_linksincludes/class-settings.php:20
Maintenance & Trust

Block Editor Disabler Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 13, 2025
PHP min version
Downloads911

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Block Editor Disabler Developer Profile

Md Khorshed Alam

2 plugins · 100 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Block Editor Disabler

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/block-editor-disabler/assets/css/block-editor-disabler.css
Script Paths
/wp-content/plugins/block-editor-disabler/assets/js/block-editor-disabler.js
Version Parameters
block-editor-disabler/assets/css/block-editor-disabler.css?ver=block-editor-disabler/assets/js/block-editor-disabler.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Block Editor Disabler