
BlocksPlus Security & Risk Analysis
wordpress.org/plugins/blocksplusA Gutenberg extension plugin, which provides often used blocks with clean and user-friendly design.
Is BlocksPlus Safe to Use in 2026?
Generally Safe
Score 85/100BlocksPlus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "blocksplus" v1.5.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, a complete reliance on prepared statements for SQL queries, and 100% proper output escaping are excellent indicators of secure coding practices. Furthermore, the presence of both nonce and capability checks on its single AJAX entry point demonstrates a thoughtful approach to preventing unauthorized access and actions. The plugin also has no recorded vulnerability history, suggesting a consistent commitment to security or a lack of past exploitable flaws.
However, while the immediate code analysis reveals no critical vulnerabilities, a comprehensive risk assessment requires ongoing vigilance. The limited attack surface, consisting solely of one AJAX handler without explicit auth checks mentioned, might be a minor concern if that handler were to perform sensitive operations without robust internal validation, though the presence of a nonce and capability check mitigates this significantly. The lack of any identified taint flows is positive, but it's important to remember that static analysis might not catch all complex or logic-based vulnerabilities.
Overall, "blocksplus" v1.5.0 appears to be a secure plugin, characterized by good development practices and a clean vulnerability history. The static analysis provides strong reassurance of its robustness. Continued monitoring for new vulnerabilities and a deeper review of the specific AJAX handler's functionality in a real-world context would be the only logical next steps for absolute certainty.
BlocksPlus Security Vulnerabilities
BlocksPlus Code Analysis
Output Escaping
Data Flow Analysis
BlocksPlus Attack Surface
AJAX Handlers 1
WordPress Hooks 12
Maintenance & Trust
BlocksPlus Maintenance & Trust
Maintenance Signals
Community Trust
BlocksPlus Alternatives
Image Comparison
image-comparison
Let the visitors compare images & make your website interactive
Firelight Lightbox
easy-fancybox
Formerly Easy Fancybox. The most popular WordPress lightbox plugin. Simple, fast, and responsive. Opens images, videos, PDFs, and custom popups.
Lightbox & Modal Popup WordPress Plugin – FooBox
foobox-image-lightbox
A responsive image lightbox for WordPress galleries, WordPress attachments & FooGallery
Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions
popup-anything-on-click
Create popup on a page load or Create popup by clicking link, image and button. Create popups, opt-in forms, & exit popups, floating bars and more!
Accordions
accordions
Create sleek accordions, tabs, FAQs, and image accordions with a React builder featuring advanced styling, animations, OpenAI support, and customizati …
BlocksPlus Developer Profile
1 plugin · 10 total installs
How We Detect BlocksPlus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/blocksplus/dist/styles/main.css/wp-content/plugins/blocksplus/dist/scripts/main.js/wp-content/plugins/blocksplus/dist/scripts/faqBlock.js/wp-content/plugins/blocksplus/dist/scripts/imageComparisonBlock.js/wp-content/plugins/blocksplus/dist/scripts/modalBlock.js/wp-content/plugins/blocksplus/dist/scripts/socialShareButtonsBlock.js/wp-content/plugins/blocksplus/dist/styles/admin.css/wp-content/plugins/blocksplus/dist/scripts/admin.js/wp-content/plugins/blocksplus/dist/scripts/main.js/wp-content/plugins/blocksplus/dist/scripts/faqBlock.js/wp-content/plugins/blocksplus/dist/scripts/imageComparisonBlock.js/wp-content/plugins/blocksplus/dist/scripts/modalBlock.js/wp-content/plugins/blocksplus/dist/scripts/socialShareButtonsBlock.js/wp-content/plugins/blocksplus/dist/scripts/admin.jsblocksplus-style?ver=1.2.0blocksplus-admin?ver=1.2.0HTML / DOM Fingerprints
blocksplus_adminblocksplus_ajax