
Convert to Blocks Security & Risk Analysis
wordpress.org/plugins/convert-to-blocksConvert to Blocks transforms classic editor content to blocks on-the-fly.
Is Convert to Blocks Safe to Use in 2026?
Generally Safe
Score 98/100Convert to Blocks has a strong security track record. Known vulnerabilities have been patched promptly.
The "convert-to-blocks" plugin v1.3.4 exhibits a mixed security posture. On the positive side, static analysis reveals a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. The code also demonstrates good practices in database interactions, with all SQL queries using prepared statements and a high percentage of output being properly escaped. Furthermore, the presence of a capability check is a positive indicator of access control implementation.
However, the plugin's vulnerability history is a significant concern. It has a known critical CVE related to "Improperly Controlled Modification of Dynamically-Determined Object Attributes." While this specific vulnerability is reported as patched, the existence of a critical flaw in the past warrants caution. The lack of nonce checks on any entry points, though the attack surface is currently zero, could become a weakness if new entry points are introduced in future updates without proper security considerations. The single file operation also presents a minor area for scrutiny, though without more context, its risk is difficult to fully assess.
In conclusion, while the current code analysis suggests a relatively clean implementation with good handling of SQL and output, the past critical vulnerability indicates a potential for serious security flaws to exist or emerge. The absence of any recorded vulnerabilities in the static analysis is reassuring, but the historical context necessitates vigilance, particularly regarding the management of dynamically determined object attributes. Future updates should be closely monitored for any new vulnerabilities.
Key Concerns
- Past critical vulnerability (unpatched)
- 0 Nonce checks on entry points
Convert to Blocks Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Minimist <= 1.2.5 - Prototype Pollution
Convert to Blocks Code Analysis
Output Escaping
Convert to Blocks Attack Surface
WordPress Hooks 17
Maintenance & Trust
Convert to Blocks Maintenance & Trust
Maintenance Signals
Community Trust
Convert to Blocks Alternatives
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Starter Templates – AI-Powered Templates for Elementor & Gutenberg
astra-sites
The growing library of 300+ ready-to-use templates that work with all WordPress themes including Astra, Hello, OceanWP, GeneratePress and more
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Breadcrumb NavXT
breadcrumb-navxt
Adds breadcrumb navigation showing the visitor's path to their current location.
Convert to Blocks Developer Profile
23 plugins · 1.4M total installs
How We Detect Convert to Blocks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/convert-to-blocks/build/editor.js/wp-content/plugins/convert-to-blocks/build/editor.jsconvert-to-blocks/build/editor.js?ver=HTML / DOM Fingerprints
ConvertToBlocks