ShopEngine Gutenberg WooCommerce Builder Blocks Addon – All in One WooCommerce Solution Security & Risk Analysis

wordpress.org/plugins/blocks-for-shopengine

Gutenberg WooCommerce Builder Blocks. Comes with WooCommerce Template Builder, Product Comparison, Quick View, Wishlist, And Variation Swatches on you …

2K active installs v2.4.3 PHP 7.4+ WP + Updated Jul 22, 2025
gutenbergwoo-builderwoocommercewoocommerce-builderwoocommerce-gutenberg
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ShopEngine Gutenberg WooCommerce Builder Blocks Addon – All in One WooCommerce Solution Safe to Use in 2026?

Generally Safe

Score 100/100

ShopEngine Gutenberg WooCommerce Builder Blocks Addon – All in One WooCommerce Solution has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The 'blocks-for-shopengine' plugin v2.4.3 demonstrates a generally strong security posture, with excellent adherence to best practices in several key areas. The absence of known vulnerabilities (CVEs) and the complete reliance on prepared statements for all SQL queries are significant strengths, indicating a mature development process regarding data integrity and preventing SQL injection. Furthermore, the plugin boasts a very high rate of properly escaped output, minimizing the risk of cross-site scripting (XSS) vulnerabilities.

However, there are minor areas for improvement that, while not indicating immediate critical risks based on the provided data, could be strengthened. The presence of two AJAX handlers without explicit authentication checks is a point of attention, even though no specific exploitability was identified in the static analysis. While the total attack surface is small and the taint analysis found no issues, the lack of capability checks on the AJAX handlers represents a missed opportunity for defense-in-depth. The vulnerability history being completely clean is a positive indicator, suggesting the plugin has historically been secure. Overall, this plugin appears to be well-developed with a focus on secure coding, but a review of authorization for its AJAX endpoints would enhance its security further.

Key Concerns

  • AJAX handlers without capability checks
Vulnerabilities
None known

ShopEngine Gutenberg WooCommerce Builder Blocks Addon – All in One WooCommerce Solution Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ShopEngine Gutenberg WooCommerce Builder Blocks Addon – All in One WooCommerce Solution Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
8 prepared
Unescaped Output
25
927 escaped
Nonce Checks
15
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared8 total queries

Output Escaping

97% escaped952 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
<screen> (blocks\account-form-register\screen.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ShopEngine Gutenberg WooCommerce Builder Blocks Addon – All in One WooCommerce Solution Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

noprivwp_ajax_gutenova_store_cssgutenova\BlockManager.php:21
authwp_ajax_gutenova_store_cssgutenova\BlockManager.php:22
WordPress Hooks 23
filtershopengine/widgets/listblock-config.php:581
actionwoocommerce_before_add_to_cart_quantityblocks\add-to-cart\screen.php:41
actionwoocommerce_after_add_to_cart_quantityblocks\add-to-cart\screen.php:59
filterwoocommerce_before_shop_loop_item_titleblocks\archive-products\screen.php:20
filterwoocommerce_before_shop_loop_item_titleblocks\archive-products\screen.php:45
filterwoocommerce_product_get_rating_htmlblocks\archive-products\screen.php:70
actionwoocommerce_after_shop_loop_item_titleblocks\archive-products\screen.php:109
filterwoocommerce_pagination_argsblocks\archive-products\screen.php:151
actionwoocommerce_after_shop_loop_itemblocks\archive-products\screen.php:262
filterwc_priceblocks\cart-totals\screen.php:54
filterwoocommerce_cart_crosssell_idsblocks\cross-sells\screen.php:44
actionenqueue_block_editor_assetsgutenova\BlockManager.php:19
actionenqueue_block_assetsgutenova\BlockManager.php:20
filterthe_contentgutenova\BlockManager.php:23
filterblock_categories_allgutenova\BlockManager.php:24
actionenqueue_block_editor_assetsgutenova\BlockManager.php:198
actionenqueue_block_assetsplugin.php:70
actionenqueue_block_assetsplugin.php:131
actiontemplate_redirectplugin.php:152
actioninitshopengine-gutenberg-addon.php:60
actionplugins_loadedshopengine-gutenberg-addon.php:61
filterdoing_it_wrong_trigger_errorshopengine-gutenberg-addon.php:71
actionshopengine/before_loadedshopengine-gutenberg-addon.php:95
Maintenance & Trust

ShopEngine Gutenberg WooCommerce Builder Blocks Addon – All in One WooCommerce Solution Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 22, 2025
PHP min version7.4
Downloads31K

Community Trust

Rating100/100
Number of ratings1
Active installs2K
Developer Profile

ShopEngine Gutenberg WooCommerce Builder Blocks Addon – All in One WooCommerce Solution Developer Profile

Roxnor

15 plugins · 3.0M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
118 days
View full developer profile
Detection Fingerprints

How We Detect ShopEngine Gutenberg WooCommerce Builder Blocks Addon – All in One WooCommerce Solution

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/blocks-for-shopengine/blocks/assets/css/blocks.style.css/wp-content/plugins/blocks-for-shopengine/blocks/assets/js/blocks.editor.build.js/wp-content/plugins/blocks-for-shopengine/assets/css/frontend.css/wp-content/plugins/blocks-for-shopengine/assets/js/frontend.js
Version Parameters
blocks-for-shopengine/assets/css/frontend.css?ver=blocks-for-shopengine/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
shopengineshopengine-widgetshopengine-categoriesshopengine-product-categories-title
Data Attributes
data-settings
JS Globals
shopengine_gutenberg_addon_editor_localize
FAQ

Frequently Asked Questions about ShopEngine Gutenberg WooCommerce Builder Blocks Addon – All in One WooCommerce Solution