
Block Finder Security & Risk Analysis
wordpress.org/plugins/block-finderEasily find and manage Gutenberg blocks anywhere on your site.
Is Block Finder Safe to Use in 2026?
Generally Safe
Score 100/100Block Finder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "block-finder" plugin v1.0.7 demonstrates a generally good security posture with a small attack surface and no known vulnerabilities in its history. The use of prepared statements for all SQL queries is a significant strength, mitigating the risk of SQL injection. The plugin also avoids dangerous functions, file operations, and external HTTP requests, further reducing its attack surface. However, there are areas for improvement. The static analysis indicates that 64% of output is properly escaped, suggesting that the remaining 36% is not, which could lead to cross-site scripting (XSS) vulnerabilities if user-controlled data is present in these unescaped outputs. Additionally, while there's one nonce check, there are no capability checks for the single AJAX handler, meaning any authenticated user could potentially trigger this functionality, regardless of their permissions. The taint analysis, while showing no critical or high severity issues, did reveal two flows with unsanitized paths, which warrants attention to ensure these paths are handled securely. In conclusion, the plugin is relatively secure due to its clean history and good practices in SQL handling, but the potential for XSS and the lack of capability checks on the AJAX endpoint represent notable weaknesses.
Key Concerns
- Unescaped output present
- AJAX handler lacks capability checks
- Flows with unsanitized paths found
Block Finder Security Vulnerabilities
Block Finder Release Timeline
Block Finder Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Block Finder Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
Block Finder Maintenance & Trust
Maintenance Signals
Community Trust
Block Finder Alternatives
Find My Blocks – Locate blocks on your site
find-my-blocks
Find My Blocks will search and list all the blocks used across your WordPress site.
Editor Custom Color Palette
editor-custom-color-palette
Personnalisez la palette de couleurs Gutenberg,la typographie,les blocs natifs, l'éditeur et l’administration WordPress,sans blocs propriétaires.
Melonpan Block – Container
melonpan-block-container
Block that provides a container, with styling features, which can have other blocks nested.
Search & Replace Text in Blocks
search-replace-text-blocks
Search and replace text within Gutenberg text blocks directly from the block editor.
Blocks for GitHub
blocks-for-github
Easily display your GitHub profile, organization, repositories, and more within the WordPress Block Editor aka "Gutenberg".
Block Finder Developer Profile
6 plugins · 30 total installs
How We Detect Block Finder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/block-finder/build/block-finder.css/wp-content/plugins/block-finder/build/block-finder.js/wp-content/plugins/block-finder/vendor/autoload.phpblock-finder.css?ver=block-finder.js?ver=HTML / DOM Fingerprints
block-finder-empty-stateid="block-finder-form"id="post-type-selector"id="block-finder-selector"id="block-finder-results"blockFinderAjax