
Block Editor Disabler Security & Risk Analysis
wordpress.org/plugins/block-editor-disablerThis plugin for disable gutenberg editor for specific role.
Is Block Editor Disabler Safe to Use in 2026?
Generally Safe
Score 92/100Block Editor Disabler has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The block-editor-disabler plugin exhibits a generally good security posture based on the provided static analysis. The absence of any detected dangerous functions, SQL queries without prepared statements, file operations, or external HTTP requests is a strong indicator of secure coding practices. Furthermore, the high percentage of properly escaped output (98%) minimizes the risk of cross-site scripting (XSS) vulnerabilities. The plugin also has a clean vulnerability history with no recorded CVEs, which suggests a history of stable and secure development.
However, the analysis does reveal a significant concern regarding the complete lack of any capability checks or nonce checks across all entry points. While the attack surface is currently reported as zero, this absence of any authorization or security token verification is a notable weakness. If any new entry points were to be introduced in future versions, or if the current analysis missed any subtle ways to interact with the plugin, the lack of these fundamental security mechanisms would leave them completely unprotected. The taint analysis showing zero flows, while positive, might be influenced by the limited attack surface and lack of identifiable data flows, rather than a guarantee of absolute safety if the attack surface were to expand.
In conclusion, the block-editor-disabler plugin demonstrates good coding hygiene in its current implementation, with no immediate critical vulnerabilities apparent. The primary weakness lies in the absence of essential security checks like capability and nonce verification. This lack of foundational security measures represents a potential risk, especially if the plugin's functionality or interaction points evolve in the future. The clean vulnerability history is a positive sign, but it does not negate the need for robust security checks.
Key Concerns
- Missing Nonce Checks
- Missing Capability Checks
Block Editor Disabler Security Vulnerabilities
Block Editor Disabler Release Timeline
Block Editor Disabler Code Analysis
Output Escaping
Block Editor Disabler Attack Surface
WordPress Hooks 7
Maintenance & Trust
Block Editor Disabler Maintenance & Trust
Maintenance Signals
Community Trust
Block Editor Disabler Alternatives
Classic Editor on off
classic-editor-on-off
Description: Classic Editor on off is a plugin that gives the ability to turn off all or some of Gutenberg, reverting to classic editor - where needed …
Daisy Disable Blocks — Disable Gutenberg, Enable Classic Editor, Disable Block Editor
daisy-disable-blocks
Disable Gutenberg Blocks and restore the Classic Editor with a simple toggle.
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
Disable Gutenberg
disable-gutenberg
Disable Gutenberg Block Editor and restore the Classic Editor and original Edit Post screen (TinyMCE, meta boxes, etc.).
Block Editor Disabler Developer Profile
2 plugins · 100 total installs
How We Detect Block Editor Disabler
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/block-editor-disabler/assets/css/block-editor-disabler.css/wp-content/plugins/block-editor-disabler/assets/js/block-editor-disabler.jsblock-editor-disabler/assets/css/block-editor-disabler.css?ver=block-editor-disabler/assets/js/block-editor-disabler.js?ver=