
Caledros Basic Blocks Security & Risk Analysis
wordpress.org/plugins/caledros-basic-blocksIntroduces 18 lightweight blocks for the Gutenberg editor. Also includes an optional preloader for CSS stylesheets to enhance performance.
Is Caledros Basic Blocks Safe to Use in 2026?
Generally Safe
Score 100/100Caledros Basic Blocks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The caledros-basic-blocks plugin v3.1.1 exhibits a generally strong security posture with some notable exceptions. The absence of dangerous functions, file operations, external HTTP requests, and a very high rate of properly escaped output are positive indicators. The use of prepared statements for all SQL queries and the presence of nonce checks are also good practices. However, a significant concern is the presence of a single REST API route that lacks permission callbacks, creating an unprotected entry point into the plugin's functionality. This unsecured endpoint represents a potential avenue for unauthorized actions or information disclosure, depending on what the REST API route is designed to do.
The static analysis did not reveal any taint flows or critical vulnerabilities in the code. The vulnerability history is clean, with no recorded CVEs, which suggests a good track record. Despite the lack of historical vulnerabilities, the identified unprotected REST API route is a concrete risk that needs to be addressed. While the plugin demonstrates good general security hygiene, this single oversight can undermine its overall security and requires immediate attention. The small attack surface overall is a positive, but the unprotected nature of its sole entry point is a critical weakness.
Key Concerns
- Unprotected REST API route
Caledros Basic Blocks Security Vulnerabilities
Caledros Basic Blocks Code Analysis
Output Escaping
Caledros Basic Blocks Attack Surface
REST API Routes 1
WordPress Hooks 28
Maintenance & Trust
Caledros Basic Blocks Maintenance & Trust
Maintenance Signals
Community Trust
Caledros Basic Blocks Alternatives
Block Designer – Create Custom Blocks for Gutenberg Editor
block-designer
Create and design custom blocks for the WordPress Gutenberg Block Editor without any line of code.
Caledros Typewriter Animator
caledros-typewriter-animator
Adds a custom typewriter animation block to the WordPress Gutenberg editor.
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Starter Templates – AI-Powered Templates for Elementor & Gutenberg
astra-sites
The growing library of 300+ ready-to-use templates that work with all WordPress themes including Astra, Hello, OceanWP, GeneratePress and more
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
Caledros Basic Blocks Developer Profile
3 plugins · 0 total installs
How We Detect Caledros Basic Blocks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/caledros-basic-blocks/core/category-featured-img/js/cbb-add-category-img.js/wp-content/plugins/caledros-basic-blocks/core/category-featured-img/js/cbb-add-category-img.jscaledros-basic-blocks/style.css?ver=caledros-basic-blocks/editor.css?ver=caledros-basic-blocks/frontend.css?ver=caledros-basic-blocks/script.js?ver=caledros-basic-blocks/editor.script.js?ver=HTML / DOM Fingerprints
caledros-basic-blocks-blockBEGIN CALEDROS BASIC BLOCKS BLOCKEND CALEDROS BASIC BLOCKS BLOCKdata-caledros-block-attributescaledros_basic_blocks_editor_settings/wp-json/caledros-basic-blocks/v1/template-parts