Enable Customizer for Full Site Editor & Block Themes Security & Risk Analysis

wordpress.org/plugins/enable-customizer

Enable the WordPress Customizer in Block Themes

30 active installs v1.0 PHP + WP 5.6+ Updated Aug 13, 2023
blockcsscustomizerfse
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Enable Customizer for Full Site Editor & Block Themes Safe to Use in 2026?

Generally Safe

Score 85/100

Enable Customizer for Full Site Editor & Block Themes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "enable-customizer" plugin, version 1.0, exhibits an exceptionally strong security posture based on the provided static analysis. The absence of any identified attack surface, including AJAX handlers, REST API routes, shortcodes, or cron events, indicates a minimal footprint and therefore limited opportunities for exploitation. Furthermore, the code signals reveal excellent development practices, with no dangerous functions, all SQL queries using prepared statements, and all outputs being properly escaped. The lack of file operations, external HTTP requests, nonce checks, and capability checks, while contributing to a clean codebase, also presents a slight concern regarding potential functionality limitations or the assumption of extreme privilege levels.

The taint analysis further reinforces this positive assessment, showing zero flows with unsanitized paths and no critical or high-severity issues. The vulnerability history is equally clean, with no known CVEs ever recorded for this plugin. This historical data suggests a consistent focus on security by the developers, or perhaps a very niche functionality that hasn't attracted malicious attention. While the plugin demonstrates a high level of security hygiene, the complete lack of any detected entry points or checks might indicate a very simple, possibly inactive, plugin, or one that relies entirely on external mechanisms for interaction, which is not inherently a weakness but warrants consideration regarding its practical application and potential for future development that might introduce risks.

Key Concerns

  • No nonce checks detected
  • No capability checks detected
Vulnerabilities
None known

Enable Customizer for Full Site Editor & Block Themes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Enable Customizer for Full Site Editor & Block Themes Release Timeline

v1.0Current
Code Analysis
Analyzed Mar 16, 2026

Enable Customizer for Full Site Editor & Block Themes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Enable Customizer for Full Site Editor & Block Themes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioncustomize_registerenable-customizer.php:13
Maintenance & Trust

Enable Customizer for Full Site Editor & Block Themes Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedAug 13, 2023
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

Enable Customizer for Full Site Editor & Block Themes Developer Profile

Mehedi

2 plugins · 130 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Enable Customizer for Full Site Editor & Block Themes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Enable Customizer for Full Site Editor & Block Themes