
Blocky! – Additional Content Blocks Security & Risk Analysis
wordpress.org/plugins/blockyBlocky! is a revolutionary new way to manage your content and add additional sections to your page content with no theme editing required!
Is Blocky! – Additional Content Blocks Safe to Use in 2026?
Generally Safe
Score 85/100Blocky! – Additional Content Blocks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'blocky' plugin v1.2.8 presents a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and it has no recorded vulnerability history (CVEs). This suggests a generally well-maintained codebase. However, significant concerns arise from the static analysis, particularly the presence of two AJAX handlers that lack authentication checks. This creates a direct attack vector where unauthenticated users could potentially trigger these handlers, leading to unintended actions within the WordPress site.
The lack of proper output escaping (only 29% properly escaped) for 17 identified output points is another critical weakness. This significantly increases the risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts that could be executed in the browsers of other users. While taint analysis did not reveal any critical or high severity unsanitized paths, the combination of unprotected AJAX endpoints and poor output escaping represents a substantial risk.
In conclusion, while the absence of known vulnerabilities and the secure handling of SQL are commendable, the unprotected AJAX endpoints and the high percentage of unescaped output are serious security flaws that demand immediate attention. The plugin has a limited attack surface of entry points, but the unprotected nature of these points, coupled with the XSS risk, makes it a notable concern for WordPress security.
Key Concerns
- Unprotected AJAX handlers found
- Low percentage of properly escaped output
Blocky! – Additional Content Blocks Security Vulnerabilities
Blocky! – Additional Content Blocks Release Timeline
Blocky! – Additional Content Blocks Code Analysis
Output Escaping
Blocky! – Additional Content Blocks Attack Surface
AJAX Handlers 2
WordPress Hooks 11
Maintenance & Trust
Blocky! – Additional Content Blocks Maintenance & Trust
Maintenance Signals
Community Trust
Blocky! – Additional Content Blocks Alternatives
White Label CMS
white-label-cms
Customise dashboard panels and branding, hide menus plus lots more.
Widget CSS Classes
widget-css-classes
Add custom classes and ids plus first, last, even, odd, and numbered classes to your widgets.
Scripts n Styles
scripts-n-styles
This plugin allows Admin users to individually add HTML, custom CSS, Classes and JavaScript directly to Post, Pages or any other custom post types.
Add Admin CSS
add-admin-css
Easily define additional CSS (inline and/or by URL) to be added to all administration pages.
Admin CSS MU
admin-css-mu
Add custom CSS to style the WordPress Admin. Works with Multisites.
Blocky! – Additional Content Blocks Developer Profile
4 plugins · 10K total installs
How We Detect Blocky! – Additional Content Blocks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/blocky/css/admin.cssHTML / DOM Fingerprints
extra_content_sectionblocky_sectiondata-blocky-versionblocky_extra_content