DBlocks Finder. Blocks and Synced Patterns Security & Risk Analysis

wordpress.org/plugins/dblocks-finder

DBlocks Finder is a WordPress plugin to easily find and manage Gutenberg blocks and synced patterns. Simple UI to find them across posts and pages.

10 active installs v1.0.8 PHP 7.4+ WP 6.1+ Updated Jan 29, 2026
blockdblocksfindergutenbergpatterns
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is DBlocks Finder. Blocks and Synced Patterns Safe to Use in 2026?

Generally Safe

Score 100/100

DBlocks Finder. Blocks and Synced Patterns has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The static analysis of the "dblocks-finder" v1.0.8 plugin indicates a generally strong security posture with no detected vulnerabilities in the analyzed code. The absence of dangerous functions, file operations, external HTTP requests, and the consistent use of prepared statements for all SQL queries are positive indicators. Furthermore, all detected outputs are properly escaped, and the plugin appears to have no critical or high-severity taint flows. The plugin also boasts a clean vulnerability history, with no recorded CVEs, suggesting a history of secure development practices.

However, a significant concern arises from the complete lack of nonce checks and capability checks. While the current attack surface is zero, this absence means that if any new entry points (AJAX handlers, REST API routes, shortcodes, or cron events) were to be introduced in future versions without proper authorization checks, they would be inherently vulnerable. This lack of robust access control mechanisms presents a latent risk that could be exploited if the plugin's functionality evolves.

In conclusion, the plugin currently demonstrates good security practices in its existing codebase. The primary weakness lies in the absence of fundamental security checks like nonce and capability checks, which are crucial for preventing unauthorized access and action. While no immediate threats are apparent, this omission is a notable area for improvement to ensure long-term security as the plugin is potentially updated.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

DBlocks Finder. Blocks and Synced Patterns Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

DBlocks Finder. Blocks and Synced Patterns Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
8 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared8 total queries
Attack Surface

DBlocks Finder. Blocks and Synced Patterns Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_menuapp\App.php:16
Maintenance & Trust

DBlocks Finder. Blocks and Synced Patterns Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.0
Last updatedJan 29, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

DBlocks Finder. Blocks and Synced Patterns Developer Profile

wpvividplugins

40 plugins · 966K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
327 days
View full developer profile
Detection Fingerprints

How We Detect DBlocks Finder. Blocks and Synced Patterns

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dblocks-finder/build/index.js/wp-content/plugins/dblocks-finder/build/index.css
Script Paths
build/index.js
Version Parameters
dblocks-finder/build/index.js?ver=dblocks-finder/build/index.css?ver=

HTML / DOM Fingerprints

JS Globals
wp_enqueue_scriptwp_enqueue_style
FAQ

Frequently Asked Questions about DBlocks Finder. Blocks and Synced Patterns