
Blocks Everywhere Security & Risk Analysis
wordpress.org/plugins/blocks-everywherePuts the Gutenberg block editor everywhere it can - bbPress, comments, and BuddyPress.
Is Blocks Everywhere Safe to Use in 2026?
Generally Safe
Score 100/100Blocks Everywhere has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "blocks-everywhere" plugin version 1.21.0 demonstrates a strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code exhibits excellent security practices with 100% of SQL queries using prepared statements and all identified outputs being properly escaped. The lack of dangerous functions, file operations, external HTTP requests, and taint flows with unsanitized paths further bolsters its security. The vulnerability history is also clean, with no recorded CVEs, indicating a history of responsible development or a lack of past exploitable issues.
While the plugin appears very secure at a code level, the absence of any AJAX handlers, REST API routes, shortcodes, or cron events is unusual for a plugin that likely aims to provide significant functionality. This could indicate a very simple plugin or one that relies entirely on other mechanisms for its operation. The lack of any nonce checks, even where capability checks are present, could be a minor oversight, though with the current attack surface analysis showing zero entry points without authentication, the immediate risk is negligible. The overall impression is a plugin developed with security in mind, adhering to best practices in critical areas, with no immediate exploitable vulnerabilities identified.
Key Concerns
- No Nonce checks detected
Blocks Everywhere Security Vulnerabilities
Blocks Everywhere Code Analysis
Output Escaping
Blocks Everywhere Attack Surface
WordPress Hooks 36
Maintenance & Trust
Blocks Everywhere Maintenance & Trust
Maintenance Signals
Community Trust
Blocks Everywhere Alternatives
Spam Destroyer
spam-destroyer
Kills spam dead in it's tracks. Be gone evil demon spam!
CBX User Online & Last Login
cbxuseronline
Shows online users based on cookie for guest and session for registered user. It also records the last login of user.
WP Notification Bell
wp-notification-bell
On-site bell notifications. Display notifications custom or triggered (new posts/cpts, WooCommerce order updates, new comment replies, bbPress...)
bbPress Login Register Links On Forum Topic Pages
bbpress-login-register-links-on-forum-topic-pages
Add bbPress only sidebar, Add bbpress login link, bbpress register link, forget password link, log out link in bbpress forum index pages or bbpress si …
Post Comments as bbPress Topics
bbpress-post-topics
Replace the comments on your WordPress blog posts with topics from an integrated bbPress install
Blocks Everywhere Developer Profile
213 plugins · 19.2M total installs
How We Detect Blocks Everywhere
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/blocks-everywhere/assets/css/blocks-everywhere.css/wp-content/plugins/blocks-everywhere/assets/js/blocks-everywhere.js/wp-content/plugins/blocks-everywhere/assets/js/blocks-everywhere.jsblocks-everywhere/assets/css/blocks-everywhere.css?ver=blocks-everywhere/assets/js/blocks-everywhere.js?ver=HTML / DOM Fingerprints
window.BlocksEverywhereEditor