
Blocks Detector Finder Security & Risk Analysis
wordpress.org/plugins/blocks-detector-finderDetect / Find Gutenberg Blocks used on pages, also detect not used Gutenberg Blocks or Missing Gutenberg Blocks.
Is Blocks Detector Finder Safe to Use in 2026?
Generally Safe
Score 85/100Blocks Detector Finder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "blocks-detector-finder" plugin v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and avoiding file operations and external HTTP requests. The taint analysis shows no evidence of unsanitized paths, indicating a low risk of critical code execution or sensitive data compromise through user input processing. Furthermore, the plugin has no recorded vulnerability history, suggesting a history of responsible development or limited exposure to security testing.
However, significant concerns arise from the attack surface analysis. The plugin exposes a single AJAX handler that lacks any authentication or capability checks. This presents a clear entry point for malicious actors to potentially trigger unintended functionality within the plugin, even without administrative privileges. The absence of nonce checks further exacerbates this risk, making it susceptible to Cross-Site Request Forgery (CSRF) attacks. While the static code analysis reveals a high percentage of properly escaped output, this doesn't mitigate the risk posed by the unprotected AJAX endpoint.
In conclusion, while the plugin's core data handling appears secure, the unprotected AJAX endpoint is a critical weakness. The lack of any authentication or nonce checks on this entry point significantly increases the risk of exploitation. The absence of past vulnerabilities is a positive sign, but it does not excuse the current oversight in securing this specific functionality. The developer should prioritize implementing proper authentication and authorization for the AJAX handler to address this significant security concern.
Key Concerns
- Unprotected AJAX handler
- Missing nonce checks on AJAX
- No capability checks on entry points
Blocks Detector Finder Security Vulnerabilities
Blocks Detector Finder Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Blocks Detector Finder Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
Blocks Detector Finder Maintenance & Trust
Maintenance Signals
Community Trust
Blocks Detector Finder Alternatives
DBlocks Finder. Blocks and Synced Patterns
dblocks-finder
DBlocks Finder is a WordPress plugin to easily find and manage Gutenberg blocks and synced patterns. Simple UI to find them across posts and pages.
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Extendify
extendify
The best WordPress templates, pattern, and layout library with 1,000+ designs built for the Gutenberg block editor.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Blocks Detector Finder Developer Profile
6 plugins · 8K total installs
How We Detect Blocks Detector Finder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/blocks-detector-finder/css/blocks-plugin-detector-finder-admin.css/wp-content/plugins/blocks-detector-finder/js/blocks-plugin-detector-finder-admin.js/wp-content/plugins/blocks-detector-finder/js/blocks-plugin-detector-finder-admin.jsblocks-detector-finder/css/blocks-plugin-detector-finder-admin.css?ver=blocks-detector-finder/js/blocks-plugin-detector-finder-admin.js?ver=