
Block Views Security & Risk Analysis
wordpress.org/plugins/block-viewsA Block-based view builder for displaying posts.
Is Block Views Safe to Use in 2026?
Generally Safe
Score 85/100Block Views has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'block-views' plugin version 1.0.0 exhibits a generally positive security posture due to the absence of known vulnerabilities and critical code signals. The plugin correctly utilizes prepared statements for all SQL queries and has a capability check in place, which are good security practices. The limited attack surface, with only one shortcode and no unprotected entry points, further contributes to its strength. However, a significant concern arises from the complete lack of output escaping for all three identified output points. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without proper sanitization.
The plugin's history of zero known CVEs and no recorded common vulnerability types is a very strong indicator of good security development and maintenance. This suggests that the developers are either very diligent or the plugin's functionality is simple enough to avoid common pitfalls. The absence of dangerous functions, file operations, and external HTTP requests also mitigates common attack vectors. Despite the positive historical data and good practices in SQL and capability checks, the unescaped output represents a tangible risk that needs to be addressed. A balanced conclusion is that while the plugin is historically secure and well-structured in many regards, the unescaped output presents a clear and actionable security weakness.
Key Concerns
- Unescaped output found
Block Views Security Vulnerabilities
Block Views Release Timeline
Block Views Code Analysis
Output Escaping
Block Views Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Block Views Maintenance & Trust
Maintenance Signals
Community Trust
Block Views Alternatives
GenerateBlocks
generateblocks
A small collection of lightweight WordPress blocks that can accomplish nearly anything.
Content Views – Post Grid & Filter, Recent Posts, Category Posts … (Shortcode, Gutenberg Blocks, and Widgets for Elementor)
content-views-query-and-display-post-page
Easy to show posts, pages, custom posts in customizable grid, list, slider, accordion... Available as Widgets (for Elementor), Shortcode, and Blocks.
Latest Posts Block – Dynamic Posts Grid, Posts List, Posts Tile with Stunning Layouts for WordPress Blogs & Pages
latest-posts-block-lite
Dynamic Posts Grid, Posts List, Posts Tile with Stunning Layouts for WordPress Blogs & Pages
Simple Definition List Blocks
simple-definition-list-blocks
A simple definition list.
Advanced Posts Blocks
advanced-posts-blocks
Create Blocks filtered by any post type and any categories, tags or custom taxonomy terms.
Block Views Developer Profile
3 plugins · 30 total installs
How We Detect Block Views
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/block-views/dist/blocks.style.build.css/wp-content/plugins/block-views/dist/blocks.build.js/wp-content/plugins/block-views/dist/blocks.editor.build.css/wp-content/plugins/block-views/dist/blocks.build.jsHTML / DOM Fingerprints
data-block="block-views/post-view"data-block="block-views/post-meta"blockViews[block_views_data