
Business Block Widget Security & Risk Analysis
wordpress.org/plugins/business-block-widgetCreate widgets to display business contact information.
Is Business Block Widget Safe to Use in 2026?
Generally Safe
Score 85/100Business Block Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The business-block-widget plugin version 1.4 exhibits a mixed security posture. On the positive side, it demonstrates strong practices in preventing SQL injection by exclusively using prepared statements. The absence of known CVEs and a clean vulnerability history suggest a potentially stable and well-maintained codebase in terms of past security issues.
However, significant concerns arise from the static analysis. The most critical finding is the use of the `create_function` function, which is known to be a security risk due to its ability to execute arbitrary code. Furthermore, the complete lack of output escaping across all 114 identified output points is a major vulnerability, leaving the plugin susceptible to Cross-Site Scripting (XSS) attacks. The absence of nonce and capability checks on entry points, while the attack surface is currently zero, indicates a lack of defensive programming that could become problematic if new entry points are introduced in future versions without proper security considerations.
In conclusion, while the plugin has a clean vulnerability history and good SQL practices, the presence of `create_function` and pervasive lack of output escaping represent critical security weaknesses. These issues require immediate attention to mitigate the risk of XSS and potential code execution vulnerabilities.
Key Concerns
- Use of dangerous function create_function
- No output escaping
- No nonce checks
- No capability checks
Business Block Widget Security Vulnerabilities
Business Block Widget Release Timeline
Business Block Widget Code Analysis
Dangerous Functions Found
Output Escaping
Business Block Widget Attack Surface
WordPress Hooks 4
Maintenance & Trust
Business Block Widget Maintenance & Trust
Maintenance Signals
Community Trust
Business Block Widget Alternatives
CT Contact
ct-contact
Want to display your personal or business contact information? Then this awesome lil' contact widget plugin is for you.
CT Social
ct-social
An awesome social plugin, featuring all of the most popular social sites.
Widgets for Google Reviews
wp-reviews-plugin-for-google
Embed Google reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Google reviews.
Astra Widgets
astra-widgets
Quickest solution to add widgets like Address, Social Profiles and List icons on a website built with Astra.
Five Star Business Profile and Schema
business-profile
Add structured data to any page or post type. Create an SEO friendly contact card with your business info and associated schema.
Business Block Widget Developer Profile
8 plugins · 180 total installs
How We Detect Business Block Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/business-block-widget/css/style.css/wp-content/plugins/business-block-widget/js/script.js/wp-content/plugins/business-block-widget/js/script.jsbusiness-block-widget/css/style.css?ver=business-block-widget/js/script.js?ver=HTML / DOM Fingerprints
business-block-widgetdata-targetdata-link-titledata-link-textdata-email-textbusinessBlockWidget