
Cloud Blocks Security & Risk Analysis
wordpress.org/plugins/cloud-blocksYour online library of Gutenberg blocks! Browse and discover new blocks, and install with a click.
Is Cloud Blocks Safe to Use in 2026?
Generally Safe
Score 85/100Cloud Blocks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cloud-blocks" plugin v1.1.8 exhibits a concerning security posture due to a significant number of unprotected AJAX handlers. With 14 AJAX handlers identified and 12 of them lacking authentication checks, the plugin presents a large attack surface that could be exploited by unauthenticated users. This is a major weakness, as it allows for potentially unauthorized actions to be performed on the WordPress site.
While the static analysis did not reveal critical vulnerabilities like dangerous functions, SQL injection via unsanitized paths, or critical taint flows, the lack of proper authorization on a majority of its entry points is a significant risk. Furthermore, the complete absence of nonce checks and capability checks on these handlers exacerbates the potential for abuse. The SQL queries also raise concerns as 100% of them are not using prepared statements, which could lead to SQL injection vulnerabilities if not handled with extreme care within the plugin's logic. The output escaping is also mediocre, with only 60% of outputs properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities.
The plugin's vulnerability history is a positive point, showing no recorded CVEs. This could indicate a history of responsible development or simply a lack of discovery due to limited adoption or prior scrutiny. However, the current static analysis findings, particularly the unprotected AJAX endpoints and the non-prepared SQL queries, create immediate and serious security risks that outweigh the clean vulnerability history. The plugin has strengths in not bundling libraries and not having critical taint flows, but these are overshadowed by the fundamental security flaws in its entry point handling and data querying.
Key Concerns
- Unprotected AJAX handlers
- Raw SQL queries without prepared statements
- Lack of nonce checks on AJAX handlers
- Lack of capability checks on AJAX handlers
- Mediocre output escaping
Cloud Blocks Security Vulnerabilities
Cloud Blocks Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Cloud Blocks Attack Surface
AJAX Handlers 14
WordPress Hooks 14
Scheduled Events 1
Maintenance & Trust
Cloud Blocks Maintenance & Trust
Maintenance Signals
Community Trust
Cloud Blocks Alternatives
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Page Builder Gutenberg Blocks – CoBlocks
coblocks
CoBlocks is a suite of page builder WordPress blocks for Gutenberg, with 10+ new blocks and a true page builder experience with rows and columns.
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
otter-blocks
Quickly create WordPress pages with 20+ blocks, 100+ ready-to-import designs, and advanced editor extensions. It’s website building, Lego-style!
Stackable – Page Builder Gutenberg Blocks
stackable-ultimate-gutenberg-blocks
Custom Blocks that transform your WordPress Block Editor into a page builder
Cloud Blocks Developer Profile
1 plugin · 30 total installs
How We Detect Cloud Blocks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cloud-blocks/assets/css/main.css/wp-content/plugins/cloud-blocks/assets/js/main.js/wp-content/plugins/cloud-blocks/core/blocks/blocks.js/wp-content/plugins/cloud-blocks/core/blocks/options.js/wp-content/plugins/cloud-blocks/core/blocks/editor.js/wp-content/plugins/cloud-blocks/core/blocks/styles.css/wp-content/plugins/cloud-blocks/assets/css/main.css?ver=/wp-content/plugins/cloud-blocks/assets/js/main.js?ver=/wp-content/plugins/cloud-blocks/core/blocks/blocks.js?ver=/wp-content/plugins/cloud-blocks/core/blocks/options.js?ver=/wp-content/plugins/cloud-blocks/core/blocks/editor.js?ver=/wp-content/plugins/cloud-blocks/core/blocks/styles.css?ver=HTML / DOM Fingerprints
fgc-block-wrapperfgc-block-editordata-fgc-block-namedata-fgc-package-namedata-fgc-js-urldata-fgc-css-urldata-fgc-editor-cssdata-fgc-info-url+4 morecloudBlocksAjaxfgc_install_block_noncefgc_get_all_blocks_noncefgc_uninstall_block_noncefgc_delete_block_noncefgc_update_block_nonce+2 more/wp-json/cloud-blocks/v1/install/wp-json/cloud-blocks/v1/get-all/wp-json/cloud-blocks/v1/uninstall/wp-json/cloud-blocks/v1/delete/wp-json/cloud-blocks/v1/update/wp-json/cloud-blocks/v1/update-version/wp-json/cloud-blocks/v1/local-blocks