DriveWorks Block – Form Embed Security & Risk Analysis

wordpress.org/plugins/driveworks-block-form-embed

Use Gutenberg blocks to quickly embed DriveWorks Projects and DriveApps.

10 active installs v1.1.0 PHP 7.0+ WP 5.8+ Updated Apr 23, 2025
blockdriveworksembedintegrationproject
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DriveWorks Block – Form Embed Safe to Use in 2026?

Generally Safe

Score 92/100

DriveWorks Block – Form Embed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "driveworks-block-form-embed" plugin version 1.1.0 exhibits an exceptionally strong security posture. The code analysis reveals no identifiable attack surface through AJAX handlers, REST API routes, shortcodes, or cron events, and crucially, none of these potential entry points are unprotected. Furthermore, the plugin demonstrates adherence to secure coding practices by avoiding dangerous functions, employing prepared statements for all SQL queries, and ensuring all output is properly escaped. The absence of file operations, external HTTP requests, nonce checks, and capability checks also contributes to a reduced risk profile.

The vulnerability history is equally positive, with zero recorded CVEs of any severity. This, coupled with the lack of any critical or high-severity taint flows in the static analysis, indicates a robust development process that actively mitigates common vulnerabilities. The plugin's strengths lie in its minimal attack surface and diligent application of secure coding principles, leading to a very low overall risk.

While the data overwhelmingly points to a secure plugin, the complete absence of nonce checks and capability checks, while currently not a direct risk due to the lack of exposed entry points, could be a potential concern if future functionality introduces new interaction points that are not properly secured. However, as it stands, the plugin presents a minimal security risk.

Vulnerabilities
None known

DriveWorks Block – Form Embed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

DriveWorks Block – Form Embed Release Timeline

v1.1.0Current
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

DriveWorks Block – Form Embed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

DriveWorks Block – Form Embed Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitdriveworks-block-form-embed.php:73
Maintenance & Trust

DriveWorks Block – Form Embed Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 23, 2025
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

DriveWorks Block – Form Embed Developer Profile

DriveWorks

2 plugins · 20 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DriveWorks Block – Form Embed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/driveworks-block-form-embed/build/index.js/wp-content/plugins/driveworks-block-form-embed/build/index.asset.php

HTML / DOM Fingerprints

CSS Classes
driveworks-block-form-embeddw-embed-error
Shortcode Output
<div class="driveworks-block-form-embed"><div class="dw-embed-error"></div></div>
FAQ

Frequently Asked Questions about DriveWorks Block – Form Embed