Block Editor for ManyChat Security & Risk Analysis

wordpress.org/plugins/block-editor-for-manychat

Easily add ManyChat widgets to your site.

100 active installs v1.0.5 PHP 7.0+ WP 5.0.0+ Updated Nov 13, 2020
botschatbotsfacebook-messengermanychatmessenger
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Block Editor for ManyChat Safe to Use in 2026?

Generally Safe

Score 85/100

Block Editor for ManyChat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The security posture of the "block-editor-for-manychat" plugin version 1.0.5 appears to be relatively strong based on the static analysis provided. The absence of identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points suggests a limited attack surface. Furthermore, the use of prepared statements for all SQL queries and the lack of dangerous functions are positive indicators of secure coding practices.

However, a significant concern arises from the fact that 100% of the identified output locations are not properly escaped. This represents a substantial risk for potential Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the site through unsanitized output. The presence of an external HTTP request, while not inherently problematic, also warrants attention to ensure it is handled securely and does not introduce further vulnerabilities. The vulnerability history being clear of any known CVEs is a good sign, but this should not lead to complacency, especially given the identified output escaping issue.

In conclusion, while the plugin demonstrates good practices in areas like SQL handling and limiting its attack surface, the critical weakness in output escaping presents a significant security risk that needs immediate attention. The lack of recorded vulnerabilities in the past is positive, but the static analysis reveals a clear and actionable area for improvement.

Key Concerns

  • Output not properly escaped
  • External HTTP request without context
Vulnerabilities
None known

Block Editor for ManyChat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Block Editor for ManyChat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Block Editor for ManyChat Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actiondivi_extensions_initdivi-manychat\divi-manychat.php:12
actionplugins_loadedincludes\class-wp-manychat.php:142
actionadmin_enqueue_scriptsincludes\class-wp-manychat.php:157
actionadmin_enqueue_scriptsincludes\class-wp-manychat.php:158
actionadmin_initincludes\class-wp-manychat.php:159
actionadmin_menuincludes\class-wp-manychat.php:160
actionadmin_initincludes\class-wp-manychat.php:161
actionadmin_initincludes\class-wp-manychat.php:162
actionenqueue_block_editor_assetsincludes\class-wp-manychat.php:163
actioninitincludes\class-wp-manychat.php:164
actionwp_enqueue_scriptsincludes\class-wp-manychat.php:179
actionwp_enqueue_scriptsincludes\class-wp-manychat.php:180
actionwp_headincludes\class-wp-manychat.php:181
actionwp_enqueue_scriptsincludes\class-wp-manychat.php:182
actionadmin_headincludes\class-wp-manychat.php:183
Maintenance & Trust

Block Editor for ManyChat Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedNov 13, 2020
PHP min version7.0
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Block Editor for ManyChat Developer Profile

simbco

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Block Editor for ManyChat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/block-editor-for-manychat/js/gutenberg.js/wp-content/plugins/block-editor-for-manychat/css/gutenberg.css/wp-content/plugins/block-editor-for-manychat/admin/css/wp-manychat-admin.css/wp-content/plugins/block-editor-for-manychat/admin/js/wp-manychat-admin.js
Script Paths
wp-blockswp-elementwp-data
Version Parameters
block-editor-for-manychat/admin/css/wp-manychat-admin.css?ver=block-editor-for-manychat/admin/js/wp-manychat-admin.js?ver=block-editor-for-manychat/js/gutenberg.js?ver=block-editor-for-manychat/css/gutenberg.css?ver=

HTML / DOM Fingerprints

Data Attributes
id="fb-page-id"
FAQ

Frequently Asked Questions about Block Editor for ManyChat