
DBlocks CodePro Security & Risk Analysis
wordpress.org/plugins/dblocks-codeproAdvanced Custom HTML Block and Code Syntax Highlightering for sharing code snippets and running code.
Is DBlocks CodePro Safe to Use in 2026?
Generally Safe
Score 100/100DBlocks CodePro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "dblocks-codepro" v1.4.4 plugin exhibits a generally good security posture, with several strong practices evident in the static analysis. Notably, it utilizes prepared statements for all SQL queries, demonstrates a high percentage of properly escaped output, and has no recorded vulnerabilities, including CVEs. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security. The presence of nonce checks and capability checks on entry points is also a positive sign.
However, a significant concern is the presence of an unprotected REST API route. While the overall attack surface is small, this single unprotected endpoint represents a direct avenue for potential exploitation, especially if it handles user-supplied input. The taint analysis shows no critical or high severity unsanitized flows, which is reassuring, but the existence of an unprotected entry point still introduces risk that should not be overlooked.
Given the plugin's clean vulnerability history, it suggests a developer who is likely attentive to security. The strengths in SQL and output handling are commendable. The main weakness lies in the single unprotected REST API route, which, despite the lack of known vulnerabilities, presents an inherent risk that could be mitigated with proper permission callbacks. Overall, the plugin is in a reasonably secure state but requires attention to the unprotected REST API.
Key Concerns
- Unprotected REST API route found
- Less than 100% output escaping
DBlocks CodePro Security Vulnerabilities
DBlocks CodePro Code Analysis
Output Escaping
Data Flow Analysis
DBlocks CodePro Attack Surface
AJAX Handlers 2
REST API Routes 1
WordPress Hooks 14
Maintenance & Trust
DBlocks CodePro Maintenance & Trust
Maintenance Signals
Community Trust
DBlocks CodePro Alternatives
Plum Code Box
plum-code-box
Plum Code Box makes it easy to insert and manage code blocks using the Chili javascript syntax highlighter.
Advance Custom HTML – Show Live Code, Share Snippets, Embed Code, and Style Them Your Way.
advance-custom-html
Advance Custom HTML lets you write and display HTML, CSS, PHP, and other code snippets on WordPress with live preview and syntax highlighting.
WPS HTML Blocks
wps-html-blocks
This plugin adds a custom HTML post type, with shortcode to place anywhere on your site.
Code Manager
code-manager
Write, test and deploy PHP, JavaScript, CSS and HTML code blocks from the WordPress dashboard.
Dev Content Blocks
dev-content-blocks
Content blocks for global content, with revisions. Use HTML without formatting being broken. Not only for devs.
DBlocks CodePro Developer Profile
40 plugins · 966K total installs
How We Detect DBlocks CodePro
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dblocks-codepro/inc/monaco-config.js/wp-content/plugins/dblocks-codepro/inc/api.js/wp-content/plugins/dblocks-codepro/build/footer-editor/index.js/wp-content/plugins/dblocks-codepro/build/footer-editor/style-index.css/wp-content/plugins/dblocks-codepro/vendor/highlight/highlight.min.js/wp-content/plugins/dblocks-codepro/vendor/highlight/languages/css.min.js/wp-content/plugins/dblocks-codepro/vendor/highlight/languages/javascript.min.js/wp-content/plugins/dblocks-codepro/vendor/highlight/languages/json.min.js+10 more/wp-content/plugins/dblocks-codepro/vendor/monaco/min/vs/loader.js/wp-content/plugins/dblocks-codepro/inc/monaco-config.js/wp-content/plugins/dblocks-codepro/inc/api.js/wp-content/plugins/dblocks-codepro/build/footer-editor/index.js/wp-content/plugins/dblocks-codepro/vendor/highlight/highlight.min.js/wp-content/plugins/dblocks-codepro/vendor/highlight/languages/css.min.js+10 moredblocks-monaco-loader?ver=1.0dblocks-monaco-config?ver=1.0dblocks-codepro-api?ver=1.0dblocks-footer-editor?ver=dblocks-footer-editor?ver=highlightjs-core?ver=1.0.0hl-language-css?ver=1.0.0hl-language-javascript?ver=1.0.0hl-language-json?ver=1.0.0hl-language-php?ver=1.0.0hl-language-plaintext?ver=1.0.0hl-language-scss?ver=1.0.0hl-language-shell?ver=1.0.0hl-language-twig?ver=1.0.0hl-language-typescript?ver=1.0.0hl-language-xml?ver=1.0.0hl-language-yaml?ver=1.0.0hl-theme-light?ver=1.0.0hl-theme-dark?ver=1.0.0HTML / DOM Fingerprints
monaco-placeholdermonaco-editor-containerDBlocksCodePro