Blocky! – Additional Content Blocks Security & Risk Analysis

wordpress.org/plugins/blocky

Blocky! is a revolutionary new way to manage your content and add additional sections to your page content with no theme editing required!

20 active installs v1.2.8 PHP + WP 4.2+ Updated Sep 10, 2015
adminbuilderclasscmscss
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Blocky! – Additional Content Blocks Safe to Use in 2026?

Generally Safe

Score 85/100

Blocky! – Additional Content Blocks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'blocky' plugin v1.2.8 presents a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and it has no recorded vulnerability history (CVEs). This suggests a generally well-maintained codebase. However, significant concerns arise from the static analysis, particularly the presence of two AJAX handlers that lack authentication checks. This creates a direct attack vector where unauthenticated users could potentially trigger these handlers, leading to unintended actions within the WordPress site.

The lack of proper output escaping (only 29% properly escaped) for 17 identified output points is another critical weakness. This significantly increases the risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts that could be executed in the browsers of other users. While taint analysis did not reveal any critical or high severity unsanitized paths, the combination of unprotected AJAX endpoints and poor output escaping represents a substantial risk.

In conclusion, while the absence of known vulnerabilities and the secure handling of SQL are commendable, the unprotected AJAX endpoints and the high percentage of unescaped output are serious security flaws that demand immediate attention. The plugin has a limited attack surface of entry points, but the unprotected nature of these points, coupled with the XSS risk, makes it a notable concern for WordPress security.

Key Concerns

  • Unprotected AJAX handlers found
  • Low percentage of properly escaped output
Vulnerabilities
None known

Blocky! – Additional Content Blocks Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Blocky! – Additional Content Blocks Release Timeline

v1.2.8Current
v1.2.7
v1.2.6
v1.2.5
v1.2.4
v1.2.3
v1.2.2
v1.2.1
v1.2.0
v1.1.3
v1.1.2
v1.1.1
v1.1.0
v1.0.2
v1.0.1
Code Analysis
Analyzed Mar 16, 2026

Blocky! – Additional Content Blocks Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
5 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

29% escaped17 total outputs
Attack Surface
2 unprotected

Blocky! – Additional Content Blocks Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

noprivwp_ajax_ajax_wp_editorblocky.php:30
authwp_ajax_ajax_wp_editorblocky.php:31
WordPress Hooks 11
actionadd_meta_boxesblocky.php:27
actionsave_postblocky.php:28
actionadmin_enqueue_scriptsblocky.php:29
actionadmin_noticesblocky.php:32
actionadmin_initblocky.php:33
actionadmin_menublocky.php:34
filterthe_contentblocky.php:37
filtertiny_mce_before_initblocky.php:38
filterwpseo_pre_analysis_post_contentblocky.php:39
filterbody_classblocky.php:41
actionadmin_initblocky.php:276
Maintenance & Trust

Blocky! – Additional Content Blocks Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedSep 10, 2015
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Blocky! – Additional Content Blocks Developer Profile

Cameron Jones

4 plugins · 10K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
668 days
View full developer profile
Detection Fingerprints

How We Detect Blocky! – Additional Content Blocks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/blocky/css/admin.css

HTML / DOM Fingerprints

CSS Classes
extra_content_sectionblocky_section
Data Attributes
data-blocky-version
JS Globals
blocky_extra_content
FAQ

Frequently Asked Questions about Blocky! – Additional Content Blocks