DigiBlocks – Professional Gutenberg Block Collection Security & Risk Analysis

wordpress.org/plugins/digiblocks

DigiBlocks is a powerful collection of beautifully designed Gutenberg blocks that help you create stunning WordPress pages with ease.

10 active installs v1.1.0 PHP 7.4+ WP 6.0+ Updated Dec 25, 2025
blockseditorgutenberggutenberg-blockspage-builder
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DigiBlocks – Professional Gutenberg Block Collection Safe to Use in 2026?

Generally Safe

Score 100/100

DigiBlocks – Professional Gutenberg Block Collection has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The digiblocks v1.1.0 plugin demonstrates a strong security posture with excellent practices in several key areas. The static analysis reveals a complete absence of dangerous functions and a commendable 100% usage of prepared statements for all SQL queries. Furthermore, all output is properly escaped, and all detected entry points (AJAX and REST API) are protected with appropriate authorization and permission checks, indicating diligent developer attention to preventing common web vulnerabilities. The lack of any recorded CVEs, past or present, is a significant positive indicator of the plugin's historical security reliability.

Despite the strong overall security, there are minor areas for consideration. The taint analysis identified two flows with unsanitized paths. While these did not result in critical or high severity issues, they represent potential avenues for exploitation if input validation or sanitization were to be less robust in a future update or if the context of these unsanitized paths is more sensitive than initially assessed. The presence of file operations and external HTTP requests, while not inherently insecure, always introduces a layer of complexity and potential risk that requires careful monitoring. The plugin's strengths in secure coding practices, particularly regarding SQL and output, far outweigh the minor concerns raised by the taint analysis. It appears to be a well-developed and security-conscious plugin.

Key Concerns

  • Taint flows with unsanitized paths (2)
Vulnerabilities
None known

DigiBlocks – Professional Gutenberg Block Collection Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

DigiBlocks – Professional Gutenberg Block Collection Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
5
7937 escaped
Nonce Checks
10
Capability Checks
9
File Operations
5
External Requests
16
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

100% escaped7942 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
ajax_download_image (includes\class-digiblocks-image-api-handler.php:67)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

DigiBlocks – Professional Gutenberg Block Collection Attack Surface

Entry Points15
Unprotected0

AJAX Handlers 12

authwp_ajax_digiblocks_submit_formincludes\class-digiblocks-forms-handler.php:39
noprivwp_ajax_digiblocks_submit_formincludes\class-digiblocks-forms-handler.php:40
authwp_ajax_digiblocks_search_imagesincludes\class-digiblocks-image-api-handler.php:22
authwp_ajax_digiblocks_download_imageincludes\class-digiblocks-image-api-handler.php:23
authwp_ajax_digiblocks_install_pluginincludes\class-digiblocks-install.php:61
authwp_ajax_digiblocks_activate_pluginincludes\class-digiblocks-install.php:62
authwp_ajax_digiblocks_install_themeincludes\class-digiblocks-install.php:63
authwp_ajax_digiblocks_activate_themeincludes\class-digiblocks-install.php:64
authwp_ajax_digiblocks_newsletter_subscribeincludes\class-digiblocks-newsletter-handler.php:39
noprivwp_ajax_digiblocks_newsletter_subscribeincludes\class-digiblocks-newsletter-handler.php:40
authwp_ajax_digiblocks_dismiss_review_noticeincludes\class-digiblocks-review-notice.php:30
authwp_ajax_digiblocks_get_menu_itemsincludes\helpers.php:462

REST API Routes 3

POST/wp-json/digiblocks/v1/update-settingsincludes\class-digiblocks.php:2137
POST/wp-json/digiblocks/v1/update-blocksincludes\class-digiblocks.php:2149
POST/wp-json/digiblocks/v1/regenerate-assetsincludes\class-digiblocks.php:2161
WordPress Hooks 26
actionwp_enqueue_scriptsincludes\class-digiblocks-fonts.php:68
actionsave_postincludes\class-digiblocks-fonts.php:79
actiondeleted_postincludes\class-digiblocks-fonts.php:82
actionadmin_noticesincludes\class-digiblocks-review-notice.php:27
actionadmin_enqueue_scriptsincludes\class-digiblocks-review-notice.php:33
filterblock_categories_allincludes\class-digiblocks.php:96
actionrest_api_initincludes\class-digiblocks.php:99
actionenqueue_block_editor_assetsincludes\class-digiblocks.php:102
actionenqueue_block_assetsincludes\class-digiblocks.php:103
actionadmin_enqueue_scriptsincludes\class-digiblocks.php:106
actionadmin_menuincludes\class-digiblocks.php:109
actionsave_postincludes\class-digiblocks.php:112
actionsave_postincludes\class-digiblocks.php:115
actiondelete_postincludes\class-digiblocks.php:116
actionsave_postincludes\class-digiblocks.php:119
actiondelete_postincludes\class-digiblocks.php:120
actionwp_trash_postincludes\class-digiblocks.php:121
actionuntrash_postincludes\class-digiblocks.php:122
filterexcerpt_allowed_blocksincludes\class-digiblocks.php:125
actionwp_enqueue_scriptsincludes\class-digiblocks.php:128
actiondeleted_postincludes\class-digiblocks.php:131
actioninitincludes\class-digiblocks.php:137
actionwp_after_insert_postincludes\class-digiblocks.php:141
actiondelete_postincludes\class-digiblocks.php:142
filteradmin_footer_textincludes\class-digiblocks.php:146
filterupdate_footerincludes\class-digiblocks.php:147
Maintenance & Trust

DigiBlocks – Professional Gutenberg Block Collection Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 25, 2025
PHP min version7.4
Downloads589

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

DigiBlocks – Professional Gutenberg Block Collection Developer Profile

DigiHold

5 plugins · 180 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DigiBlocks – Professional Gutenberg Block Collection

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/digiblocks/assets/css/blocks.style.build.css/wp-content/plugins/digiblocks/assets/js/blocks.editor.build.js/wp-content/plugins/digiblocks/assets/js/blocks.build.js
Script Paths
/wp-content/plugins/digiblocks/assets/js/blocks.editor.build.js/wp-content/plugins/digiblocks/assets/js/blocks.build.js
Version Parameters
digiblocks/assets/css/blocks.style.build.css?ver=digiblocks/assets/js/blocks.editor.build.js?ver=digiblocks/assets/js/blocks.build.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-block-digiblocks
HTML Comments
<!-- wp:digiblocks/<!-- /wp:digiblocks/
Data Attributes
data-block="digiblocksdata-type="digiblocks
JS Globals
wp.blocks.getBlockTypes().filter(block => block.name.includes('digiblocks'))wp.data.select('core/editor').getBlocks()window.wp.blocks.getBlockTypes()wp.blocks.unregisterBlockTypewp.blocks.registerBlockType
Shortcode Output
[digiblocks[/digiblocks]
FAQ

Frequently Asked Questions about DigiBlocks – Professional Gutenberg Block Collection