BlockGlow — Per-block Custom CSS Security & Risk Analysis

wordpress.org/plugins/blockglow

Adds a "Custom CSS" inspector panel to every Gutenberg block and saves per-block CSS files to uploads for front-end enqueuing.

0 active installs v1.1.7 PHP 8.2+ WP 5.8+ Updated Jan 11, 2026
blockscsscustom-csseditorgutenberg
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BlockGlow — Per-block Custom CSS Safe to Use in 2026?

Generally Safe

Score 100/100

BlockGlow — Per-block Custom CSS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The static analysis of blockglow v1.1.7 reveals a generally strong security posture. The plugin exhibits excellent practices regarding SQL queries, utilizing prepared statements exclusively. Furthermore, a high percentage of output is properly escaped, and a reasonable number of nonce and capability checks are present. The absence of critical or high-severity taint flows, dangerous functions, external HTTP requests, and a minimal attack surface (zero entry points) are significant strengths.

However, the presence of file operations, even if not immediately flagged as problematic in the static analysis, warrants cautious consideration. While the data doesn't indicate any direct vulnerabilities related to these operations, any interaction with the file system can introduce potential risks if not meticulously handled. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator of past security diligence. This, combined with the current positive static analysis, suggests a well-maintained and secure plugin.

In conclusion, blockglow v1.1.7 appears to be a secure plugin with robust security practices in place, particularly concerning data handling and access control. The clean vulnerability history further reinforces this assessment. The only area to remain observant about is the file operations, although no immediate threats are identified from the provided data.

Key Concerns

  • File operations present, requires careful review
Vulnerabilities
None known

BlockGlow — Per-block Custom CSS Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

BlockGlow — Per-block Custom CSS Release Timeline

v1.1.7Current
v1.1.6
Code Analysis
Analyzed Mar 17, 2026

BlockGlow — Per-block Custom CSS Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
53 escaped
Nonce Checks
6
Capability Checks
7
File Operations
5
External Requests
0
Bundled Libraries
0

Output Escaping

90% escaped59 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
render_tab_content (admin\class-blockglow-css-manager.php:105)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

BlockGlow — Per-block Custom CSS Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_menuadmin\class-blockglow-admin.php:24
actionadmin_enqueue_scriptsadmin\class-blockglow-admin.php:25
actionadmin_post_blockglow_delete_fileadmin\class-blockglow-admin.php:26
actionadmin_post_blockglow_clear_all_filesadmin\class-blockglow-css-manager.php:19
actionadmin_post_blockglow_delete_fileadmin\class-blockglow-css-manager.php:20
actionadmin_post_blockglow_bulk_delete_selectedadmin\class-blockglow-css-manager.php:21
actionenqueue_block_editor_assetsblockglow.php:133
filterrender_blockblockglow.php:288
actionwp_print_footer_scriptsblockglow.php:375
Maintenance & Trust

BlockGlow — Per-block Custom CSS Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 11, 2026
PHP min version8.2
Downloads179

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

BlockGlow — Per-block Custom CSS Developer Profile

Mary Rose Elbambo

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BlockGlow — Per-block Custom CSS

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/blockglow/assets/js/blockglow-editor.js/wp-content/plugins/blockglow/assets/dist/editor.min.js
Script Paths
/wp-content/plugins/blockglow/assets/js/blockglow-editor.js/wp-content/plugins/blockglow/assets/dist/editor.min.js
Version Parameters
blockglow/assets/dist/assets/blockglow-editor-styleblockglow-editor

HTML / DOM Fingerprints

Data Attributes
data-blockglow-id
JS Globals
BlockGlowData
FAQ

Frequently Asked Questions about BlockGlow — Per-block Custom CSS