
Create Block Theme Security & Risk Analysis
wordpress.org/plugins/create-block-themeA WordPress plugin to create block themes.
Is Create Block Theme Safe to Use in 2026?
Generally Safe
Score 98/100Create Block Theme has a strong security track record. Known vulnerabilities have been patched promptly.
The create-block-theme plugin v2.9.0 exhibits a generally strong security posture, with excellent practices observed in its code. The static analysis reveals a clean codebase, with no dangerous functions, entirely prepared SQL statements, and a very high percentage of properly escaped output. The plugin also demonstrates good practice by having a comprehensive set of capability checks for its REST API routes, indicating an effort to restrict access to authorized users.
However, a significant concern arises from the plugin's vulnerability history. The presence of one critical vulnerability, specifically an 'Unrestricted Upload of File with Dangerous Type', although currently patched, suggests a past weakness in handling file uploads that could have led to severe security breaches. The absence of taint analysis results is noted, which might limit the understanding of potential data flow vulnerabilities, although the lack of critical or high severity flows in the limited analysis is a positive sign.
In conclusion, while the current version of create-block-theme v2.9.0 appears to implement robust security measures, the historical critical vulnerability warrants caution. Users should ensure they are always on the latest patched version and be aware of the potential risks associated with file upload functionalities in any plugin. The plugin's strengths lie in its secure coding practices for SQL and output, but its past critical vulnerability highlights a potential area for ongoing vigilance.
Key Concerns
- Past critical vulnerability (Unrestricted Upload)
- 0 Taint flows analyzed, potential blind spot
- 0 Nonce checks found
Create Block Theme Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Create Block Theme <= 1.2.1 - Unauthenticated Arbitrary File Upload
Create Block Theme Code Analysis
Output Escaping
Create Block Theme Attack Surface
REST API Routes 9
WordPress Hooks 5
Maintenance & Trust
Create Block Theme Maintenance & Trust
Maintenance Signals
Community Trust
Create Block Theme Alternatives
Disable Auto Update Emails and Block Updates for Plugins, WP Core, and Themes
disable-email-notification-for-auto-updates
This plugin disables email notifications for auto-updates and blocks updates for specific plugins, hide plugins, WordPress core, and themes.
Ajaxified Cart
ajaxified-cart-woocommerce
AJAX add-to-cart for WooCommerce: simple & variable products on archives/blocks via accessible modal and instant cart refresh.
Classic Menus for Block Themes
classic-menus-for-block-themes
Short Description: Re-enable the legacy menu management system alongside block-based WordPress themes.
Block Theme Color Switcher
block-theme-color-switcher
Front-end color palette switcher for Block Themes. Let users pick styles instantly. Perfect for theme demos & developer showcases.
Child Theme Configurator
child-theme-configurator
When using the Customizer is not enough - Create a child theme from your installed themes and customize styles, templates, functions and more.
Create Block Theme Developer Profile
34 plugins · 14.9M total installs
How We Detect Create Block Theme
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/create-block-theme/build/admin-landing-page.css/wp-content/plugins/create-block-theme/build/admin-landing-page.js/wp-content/plugins/create-block-theme/build/plugin-sidebar.css/wp-content/plugins/create-block-theme/build/plugin-sidebar.js/wp-content/plugins/create-block-theme/build/admin-landing-page.js/wp-content/plugins/create-block-theme/build/plugin-sidebar.jscreate-block-theme-appcreate-block-theme-stylescreate-block-theme-slot-fillHTML / DOM Fingerprints
cbt_landingpage_variablesWP_VERSION/wp-json/create-block-theme/v1/export/wp-json/create-block-theme/v1/update/wp-json/create-block-theme/v1/save/wp-json/create-block-theme/v1/clone/wp-json/create-block-theme/v1/create-variation/wp-json/create-block-theme/v1/create-blank/wp-json/create-block-theme/v1/create-child/wp-json/create-block-theme/v1/font-families/wp-json/create-block-theme/v1/reset-theme<div id="create-block-theme-app"></div>