
Content Blocks (Custom Post Widget) Security & Risk Analysis
wordpress.org/plugins/custom-post-widgetThis plugin enables you to edit and display Content Blocks in a sidebar widget or using a shortcode.
Is Content Blocks (Custom Post Widget) Safe to Use in 2026?
Generally Safe
Score 96/100Content Blocks (Custom Post Widget) has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of the 'custom-post-widget' plugin v3.4.1 reveals a generally good security posture with several strengths. Notably, there are no observed dangerous functions, all SQL queries use prepared statements, and file operations and external HTTP requests are absent. The plugin also demonstrates a decent effort in securing its entry points, with a high percentage of outputs properly escaped and a good number of capability checks in place. The presence of a nonce check is also a positive sign.
Key Concerns
- Significant historical vulnerability count
- Previous Cross-site Scripting (XSS) vulnerabilities
- Previous PHP Remote File Inclusion vulnerabilities
- Moderate unescaped output percentage
Content Blocks (Custom Post Widget) Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Content Blocks (Custom Post Widget) <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via content Parameter
Content Blocks (Custom Post Widget) <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Content Blocks (Custom Post Widget) <= 3.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via content_block Shortcode
Content Blocks (Custom Post Widget) <= 3.3.0 - Authenticated (Contributor+) Local File Inclusion via Shortcode
Content Blocks (Custom Post Widget) <= 3.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Content Blocks (Custom Post Widget) Code Analysis
Output Escaping
Content Blocks (Custom Post Widget) Attack Surface
Shortcodes 2
WordPress Hooks 17
Maintenance & Trust
Content Blocks (Custom Post Widget) Maintenance & Trust
Maintenance Signals
Community Trust
Content Blocks (Custom Post Widget) Alternatives
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Reusable Blocks Extended
reusable-blocks-extended
Extend Gutenberg Reusable Blocks feature with a complete admin panel, widgets, shortcodes and PHP functions.
Reusable Content Blocks
reusable-content-blocks
Reusable Content Blocks plugin allows you to insert contents (pages, posts, custom post types) created with WPBakery Page Builder into other contents, …
List Last Changes
list-last-changes
Shows a list of the last changes of a WordPress site.
Simple Ticker
simple-ticker
Displays the ticker.
Content Blocks (Custom Post Widget) Developer Profile
4 plugins · 25K total installs
How We Detect Content Blocks (Custom Post Widget)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-post-widget/assets/css/custom-post-widget.css/wp-content/plugins/custom-post-widget/assets/js/clipboard-init.jswp-content/plugins/custom-post-widget/assets/js/clipboard-init.jscustom-post-widget.css?ver=clipboard-init.js?ver=HTML / DOM Fingerprints
content_blockdata-clipboard-textclipboard<div class="content_block"><div class='content_block_wrapper'><div class='content_block_title'><h3 class='content_block_title'>