
Gutenberg Blocks Library & Toolkit – Editor Plus Security & Risk Analysis
wordpress.org/plugins/editorplusEditor Plus extends Gutenberg editor with blocks, advanced design controls, typography, icons, Shape Divider, animations and many more features.
Is Gutenberg Blocks Library & Toolkit – Editor Plus Safe to Use in 2026?
Generally Safe
Score 85/100Gutenberg Blocks Library & Toolkit – Editor Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of editorplus v2.10.0 reveals a surprisingly clean codebase with no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events. This significantly reduces the potential attack surface. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and importantly, nonce or capability checks suggests a strong emphasis on secure development practices, at least in these specific areas. The taint analysis also shows no identified vulnerabilities.
However, the analysis does highlight some areas of concern. The presence of a single SQL query that does not utilize prepared statements is a direct risk of SQL injection. Similarly, the fact that 100% of the identified output operations are not properly escaped poses a significant risk of Cross-Site Scripting (XSS) vulnerabilities. The plugin also bundles Lodash, which, if outdated, could introduce further risks, although the data does not specify its version or whether it's outdated.
The plugin's vulnerability history is remarkably clean, with zero known CVEs. This indicates a good track record for security. However, the limited scope of the static analysis (0 taint flows) and the lack of comprehensive checks in areas like SQL and output escaping mean that the absence of past vulnerabilities might be more due to luck or a smaller attack surface than robust, universally applied security measures. Despite the lack of past issues, the identified code-level risks require attention.
Key Concerns
- SQL queries not using prepared statements
- Output not properly escaped
- Bundled library (Lodash) potentially outdated
Gutenberg Blocks Library & Toolkit – Editor Plus Security Vulnerabilities
Gutenberg Blocks Library & Toolkit – Editor Plus Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Gutenberg Blocks Library & Toolkit – Editor Plus Attack Surface
WordPress Hooks 17
Maintenance & Trust
Gutenberg Blocks Library & Toolkit – Editor Plus Maintenance & Trust
Maintenance Signals
Community Trust
Gutenberg Blocks Library & Toolkit – Editor Plus Alternatives
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Superb Addons: Blocks, Patterns & Theme Designer for the Block Editor & FSE
superb-blocks
Create beautiful WordPress websites easily with 10+ blocks, 200+ patterns, 100+ pre-built pages, animations and Theme Designer. No coding needed!
GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor
gutenkit-blocks-addon
GutenKit – Ultimate no-code Gutenberg blocks to design stunning web pages and visually stunning posts in WordPress block editor.
Gutenberg Blocks Library & Toolkit – Editor Plus Developer Profile
8 plugins · 49K total installs
How We Detect Gutenberg Blocks Library & Toolkit – Editor Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/editorplus/dist/gutenberg-editor-style.css/wp-content/plugins/editorplus/dist/gutenberg-editor.js/wp-content/plugins/editorplus/assets/scripts/lodash-conflict.js/wp-content/plugins/editorplus/assets/scripts/lottie-player.js/wp-content/plugins/editorplus/dist/style-gutenberg-frontend-style.css/wp-content/plugins/editorplus/assets/scripts/frontend.js/wp-content/plugins/editorplus/dist/style-admin.css/wp-content/plugins/editorplus/dist/admin.js/wp-content/plugins/editorplus/dist/gutenberg-editor.js/wp-content/plugins/editorplus/assets/scripts/lodash-conflict.js/wp-content/plugins/editorplus/assets/scripts/lottie-player.js/wp-content/plugins/editorplus/assets/scripts/frontend.js/wp-content/plugins/editorplus/dist/admin.jseditorplus/style.css?ver=editorplus-plugin-style?ver=editor_plus-plugin-script?ver=editor_plus-lodash-conflict-script?ver=editor-plus-lottie-script?ver=editor_plus-plugin-frontend-style?ver=editor_plus-plugin-frontend-script?ver=editor-plus-admin-style?ver=editor-plus-admin-script?ver=HTML / DOM Fingerprints
editor-plus-rooteditor_plus_extensioneplus_data<div id="editor-plus-root"></div>