
Blocksolid Security & Risk Analysis
wordpress.org/plugins/blocksolidAn overlay for the block editor to make it easier to use.
Is Blocksolid Safe to Use in 2026?
Generally Safe
Score 100/100Blocksolid has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The blocksolid plugin v2.1.2 demonstrates a generally good security posture. The static analysis reveals strong adherence to secure coding practices, with 100% of SQL queries utilizing prepared statements and a high rate of output escaping (94%). The absence of dangerous functions, external HTTP requests, and critical/high severity taint flows further contributes to its robustness. Furthermore, the plugin has no recorded vulnerability history, indicating a lack of publicly known exploits and a potentially mature development process.
However, a minor concern exists regarding the REST API. One out of three REST API routes lacks permission callbacks, creating an unprotected entry point. While not a critical flaw on its own, it represents a potential avenue for unauthorized access if sensitive functionality is exposed through that route. The presence of four AJAX handlers, while four have nonce checks, suggests that the remaining handlers should be carefully reviewed to ensure proper authorization and noncing are implemented to mitigate any potential risks.
In conclusion, blocksolid v2.1.2 is a well-developed plugin with strong security foundations. The primary area for improvement is addressing the unprotected REST API route to further harden its attack surface. The absence of historical vulnerabilities is a positive sign, but vigilance regarding the identified REST API and AJAX entry points is recommended.
Key Concerns
- REST API route without permission callbacks
Blocksolid Security Vulnerabilities
Blocksolid Release Timeline
Blocksolid Code Analysis
Output Escaping
Data Flow Analysis
Blocksolid Attack Surface
AJAX Handlers 4
REST API Routes 3
WordPress Hooks 26
Maintenance & Trust
Blocksolid Maintenance & Trust
Maintenance Signals
Community Trust
Blocksolid Alternatives
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
Disable Gutenberg
disable-gutenberg
Disable Gutenberg Block Editor and restore the Classic Editor and original Edit Post screen (TinyMCE, meta boxes, etc.).
Classic Editor and Classic Widgets
classic-editor-and-classic-widgets
Disables Gutenberg editor totally everywhere and enables Classic Editor and Classic Widgets.
TCD Classic Editor
tcd-classic-editor
This is a classic editor extension plug-in for TCD users. It is currently offered as a beta board.
Blocksolid Developer Profile
4 plugins · 70 total installs
How We Detect Blocksolid
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/blocksolid/css/blocksolid-settings-styles.css/wp-content/plugins/blocksolid/js/blocksolid-settings.js/wp-content/plugins/blocksolid/css/blocksolid-admin-styles.css/wp-content/plugins/blocksolid/css/blocksolid-admin-styles-6.css/wp-content/plugins/blocksolid/css/blocksolid.css/wp-content/plugins/blocksolid/js/document_ready.js/wp-content/plugins/blocksolid/js/document_ready_backgrounds.js/wp-content/plugins/blocksolid/js/document_ready_stretch_row.js/wp-content/plugins/blocksolid/js/blocksolid-settings.js/wp-content/plugins/blocksolid/js/document_ready.js/wp-content/plugins/blocksolid/js/document_ready_backgrounds.js/wp-content/plugins/blocksolid/js/document_ready_stretch_row.jsblocksolid-settings-styles?ver=blocksolid-settings?ver=blocksolid-admin-styles?ver=blocksolid-admin-styles-6?ver=blocksolid?ver=document_ready.js?ver=document_ready_backgrounds.js?ver=document_ready_stretch_row.js?ver=HTML / DOM Fingerprints
blocksolid-overlaydata-align="wide"