
Button Block – Design Stylish, Interactive, and Multi-Functional Buttons Security & Risk Analysis
wordpress.org/plugins/button-blockGet multi-functional buttons
Is Button Block – Design Stylish, Interactive, and Multi-Functional Buttons Safe to Use in 2026?
Generally Safe
Score 96/100Button Block – Design Stylish, Interactive, and Multi-Functional Buttons has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'button-block' plugin version 1.2.4 exhibits a generally good security posture, with all identified entry points (AJAX handlers, shortcodes) appearing to have appropriate authentication and capability checks. The code analysis further shows a strong adherence to secure coding practices, with no dangerous functions, no raw SQL queries, and excellent output escaping (92%). File operations and external HTTP requests are also absent, reducing potential attack vectors. The lack of taint analysis findings indicates no immediate issues with unsanitized paths.
However, the plugin's vulnerability history is a significant concern. It has a total of 5 known CVEs, all categorized as medium severity. These past vulnerabilities include common types like CSRF, missing authorization, XSS, information exposure, and authorization bypass. While none are currently unpatched, the pattern of past vulnerabilities, especially across diverse attack types, suggests a recurring struggle with robust security implementation in previous versions. This history raises questions about the thoroughness of security testing and development practices for this plugin.
In conclusion, the current version of 'button-block' benefits from strong internal security controls like nonce and capability checks, and good output sanitization. Nevertheless, the historical prevalence of medium-severity vulnerabilities across various categories warrants caution. Users should remain vigilant for future updates and be aware that past security weaknesses may re-emerge if not consistently addressed by the developers.
Key Concerns
- History of 5 medium severity CVEs
- Bundled library (Freemius)
Button Block – Design Stylish, Interactive, and Multi-Functional Buttons Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Button Block <= 1.2.0 - Cross-Site Request Forgery
Button Block <= 1.1.5 - Missing Authorization
Button Block <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Button Block – Get fully customizable & multi-functional buttons <= 1.1.5 - Authenticated (Contributor+) Post Disclosure via Post Duplication
Button Block – Get fully customizable & multi-functional buttons <= 1.1.4 - Authenticated (Contributor+) Post Disclosure
Button Block – Design Stylish, Interactive, and Multi-Functional Buttons Release Timeline
Button Block – Design Stylish, Interactive, and Multi-Functional Buttons Code Analysis
Bundled Libraries
Output Escaping
Button Block – Design Stylish, Interactive, and Multi-Functional Buttons Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 18
Maintenance & Trust
Button Block – Design Stylish, Interactive, and Multi-Functional Buttons Maintenance & Trust
Maintenance Signals
Community Trust
Button Block – Design Stylish, Interactive, and Multi-Functional Buttons Alternatives
Quick Download Button
quick-download-button
Add stylish download buttons to any post or page — 7 styles, countdown, popup modal, access control. Gutenberg block and shortcode.
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Page Builder Gutenberg Blocks – CoBlocks
coblocks
CoBlocks is a suite of page builder WordPress blocks for Gutenberg, with 10+ new blocks and a true page builder experience with rows and columns.
Button Block – Design Stylish, Interactive, and Multi-Functional Buttons Developer Profile
121 plugins · 740K total installs
How We Detect Button Block – Design Stylish, Interactive, and Multi-Functional Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/button-block/build/admin/dashboard.css/wp-content/plugins/button-block/build/admin/dashboard.js/wp-content/plugins/button-block/build/admin/general.css/wp-content/plugins/button-block/build/admin/post.css/wp-content/plugins/button-block/build/admin/post.js/wp-content/plugins/button-block/public/css/font-awesome.min.css/wp-content/plugins/button-block/public/css/aos.css/wp-content/plugins/button-block/public/js/aos.js/wp-content/plugins/button-block/build/admin/dashboard.js/wp-content/plugins/button-block/public/js/aos.jsbutton-block/build/admin/dashboard.css?ver=button-block/build/admin/dashboard.js?ver=button-block/build/admin/general.css?ver=button-block/build/admin/post.css?ver=button-block/build/admin/post.js?ver=button-block/public/css/font-awesome.min.css?ver=button-block/public/css/aos.css?ver=button-block/public/js/aos.js?ver=HTML / DOM Fingerprints
btnAdminHideSwitchsliderroundbtn-post-button-duplicatedata-infobtnpipecheckbtnpricingurl[btn_block]