
Classic Widgets with Block-based Widgets Security & Risk Analysis
wordpress.org/plugins/classic-widgets-with-block-based-widgetsRestore the classic widgets screen as a new menu item without replacing new block-based widgets.
Is Classic Widgets with Block-based Widgets Safe to Use in 2026?
Mostly Safe
Score 78/100Classic Widgets with Block-based Widgets is generally safe to use. 1 past CVE were resolved. Keep it updated.
The static analysis of "classic-widgets-with-block-based-widgets" v1.0.1 reveals a generally strong security posture regarding its immediate attack surface and code hygiene. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, indicating a minimal exposure through these common WordPress entry points. The code demonstrates excellent practices by exclusively using prepared statements for SQL queries and ensuring all outputs are properly escaped, with no detected file operations or external HTTP requests. Furthermore, the absence of critical or high severity taint analysis flows is a positive sign of secure coding.
However, a significant concern arises from the vulnerability history. The plugin has a known critical vulnerability that remains unpatched, specifically a "Missing Authorization" issue. This suggests that despite the current static analysis findings, there's a known exploit path that has not been addressed. The fact that this is the only known vulnerability, but it is critical and unpatched, indicates a potential for serious security breaches if exploited. While the current code seems clean, the historical vulnerability is a major red flag.
In conclusion, the plugin exhibits strengths in its current code quality and limited attack surface. However, the presence of an unpatched critical vulnerability, even if isolated, severely undermines its security. The "Missing Authorization" vulnerability is a serious threat that requires immediate attention, overshadowing the positive aspects of the static analysis. Users should exercise extreme caution until this critical vulnerability is resolved.
Key Concerns
- Unpatched critical vulnerability
- Missing capability checks
- Missing nonce checks
Classic Widgets with Block-based Widgets Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Classic Widgets with Block-based Widgets <= 1.0.1 - Missing Authorization
Classic Widgets with Block-based Widgets Code Analysis
Classic Widgets with Block-based Widgets Attack Surface
WordPress Hooks 6
Maintenance & Trust
Classic Widgets with Block-based Widgets Maintenance & Trust
Maintenance Signals
Community Trust
Classic Widgets with Block-based Widgets Alternatives
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets
widget-options
0ddcemmihs4a843ekhaoofzosrunf4bl Widget Options gives you super powers to control your site’s sidebar widgets and all Gutenberg blocks on pages, posts …
Classic Editor and Classic Widgets
classic-editor-and-classic-widgets
Disables Gutenberg editor totally everywhere and enables Classic Editor and Classic Widgets.
WPDevs Classic Editor & Widgets
wpdevs-classic-editor-widgets
WPDevs Classic Editor & Widgets enables the traditional WordPress classic editor, classic widgets, and the previous version of the Edit Post scree …
Custom Sidebars – Dynamic Sidebar Classic Widget Area Manager
custom-sidebars
Flexible sidebars for custom classic widget configurations on any page or post. Create custom sidebars with ease!
Classic Widgets with Block-based Widgets Developer Profile
3 plugins · 21K total installs
How We Detect Classic Widgets with Block-based Widgets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
Classic Widgets