Blocks Editor Interface Customizer Security & Risk Analysis

wordpress.org/plugins/blocks-editor-customizer

A WordPress plugin to customize the Gutenberg block editor interface, allowing adjustments to editor width, sidebar size, and enabling Dark Mode for i …

10 active installs v1.3 PHP 5.6+ WP 4.7+ Updated Unknown
appearanceblockscustomizegutenbergstyle
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Blocks Editor Interface Customizer Safe to Use in 2026?

Generally Safe

Score 100/100

Blocks Editor Interface Customizer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "blocks-editor-customizer" v1.3 plugin exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, SQL queries executed with prepared statements, and no file operations or external HTTP requests are positive indicators. Furthermore, the lack of any recorded vulnerabilities, including critical or high severity ones, suggests a history of responsible development and maintenance. The zero entry points also minimize the direct attack surface. However, a significant concern arises from the complete lack of output escaping (0% properly escaped). This means any data displayed by the plugin, even if internally sanitized, could be rendered in a way that allows for Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce and capability checks also means that even if there were entry points, they might not be adequately protected against unauthorized actions.

Key Concerns

  • No output escaping
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Blocks Editor Interface Customizer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Blocks Editor Interface Customizer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped8 total outputs
Attack Surface

Blocks Editor Interface Customizer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_initadmin\class-gutenberg-customizer-admin.php:120
actionadmin_menuadmin\class-gutenberg-customizer-admin.php:121
actionadmin_enqueue_scriptsadmin\class-gutenberg-customizer-admin.php:122
actionadmin_footeradmin\class-gutenberg-customizer-admin.php:211
actionadmin_footeradmin\class-gutenberg-customizer-admin.php:212
actionplugins_loadedincludes\class-gutenberg-customizer.php:142
actionadmin_enqueue_scriptsincludes\class-gutenberg-customizer.php:158
actionadmin_enqueue_scriptsincludes\class-gutenberg-customizer.php:159
actionwp_enqueue_scriptsincludes\class-gutenberg-customizer.php:174
actionwp_enqueue_scriptsincludes\class-gutenberg-customizer.php:175
Maintenance & Trust

Blocks Editor Interface Customizer Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedUnknown
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Blocks Editor Interface Customizer Developer Profile

THE BELOV

7 plugins · 1K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Blocks Editor Interface Customizer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/blocks-editor-customizer/admin/css/gutenberg-customizer-admin.css
Script Paths
/wp-content/plugins/blocks-editor-customizer/admin/js/gutenberg-customizer-admin.js
Version Parameters
gutenberg-customizer-admin.css?ver=gutenberg-customizer-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wrap-option-pluginwrapper-description-pluginslideriris_colorwp-picker-clearwrapper-input
HTML Comments
Currently plugin version.This function is provided for demonstration purposes only.An instance of this class should be passed to the run() functiondefined in Gutenberg_Customizer_Loader as all of the hooks are defined+4 more
Data Attributes
iris_optionsiris_color_pickgutenberg-widthmy-range-1gutenberg-width-sidebarmy-range-2
FAQ

Frequently Asked Questions about Blocks Editor Interface Customizer