Fabrica Synced Pattern Instances Security & Risk Analysis

wordpress.org/plugins/fabrica-reusable-block-instances

Shows you how many times, and where, a Synced Pattern has been used.

300 active installs v1.0.9 PHP 5.6+ WP 5.0+ Updated Nov 14, 2024
blockblockeditorblocksgutenbergreusable
91
A · Safe
CVEs total1
Unpatched0
Last CVENov 4, 2024
Safety Verdict

Is Fabrica Synced Pattern Instances Safe to Use in 2026?

Generally Safe

Score 91/100

Fabrica Synced Pattern Instances has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 4, 2024Updated 1yr ago
Risk Assessment

The 'fabrica-reusable-block-instances' plugin version 1.0.9 exhibits a generally good security posture based on the static analysis. The absence of identifiable entry points like AJAX handlers, REST API routes, shortcodes, and cron events, along with the fact that none of these (if they existed) would be unprotected, significantly reduces the plugin's attack surface. Furthermore, the code demonstrates strong adherence to secure coding practices with 100% proper output escaping and no identified dangerous functions, file operations, or external HTTP requests. The use of prepared statements for SQL queries is also positive, although 25% of them are not prepared, which represents a minor concern.

While the static analysis shows no critical or high severity taint flows, indicating no immediate vulnerabilities related to unsanitized input, the plugin has a history of a medium-severity Cross-Site Scripting (XSS) vulnerability. This vulnerability was patched relatively recently. The presence of only one prior vulnerability, and its resolution, suggests the developers are responsive to security issues. However, it also highlights that the plugin is not entirely immune to security flaws, and past XSS issues warrant continued vigilance.

In conclusion, the plugin is well-developed from a security perspective, with a minimal attack surface and robust output sanitization. The main areas for improvement are ensuring all SQL queries utilize prepared statements and maintaining vigilance against potential XSS, given its past history. The current version appears to be secure, but ongoing monitoring is recommended.

Key Concerns

  • SQL queries not using prepared statements
  • History of a medium severity XSS vulnerability
Vulnerabilities
1

Fabrica Synced Pattern Instances Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-51695medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Fabrica Synced Pattern Instances <= 1.0.8 - Reflected Cross-Site Scripting

Nov 4, 2024 Patched in 1.0.9 (12d)
Code Analysis
Analyzed Mar 16, 2026

Fabrica Synced Pattern Instances Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
3 prepared
Unescaped Output
0
23 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

75% prepared4 total queries

Output Escaping

100% escaped23 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
addPostTypesFilter (inc\base.php:117)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Fabrica Synced Pattern Instances Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionpost_updatedinc\base.php:20
actionregistered_post_typeinc\base.php:23
actionadmin_enqueue_scriptsinc\base.php:24
actionrestrict_manage_postsinc\base.php:25
actionpre_get_postsinc\base.php:28
filteresc_htmlinc\base.php:29
filterviews_edit-wp_blockinc\base.php:30
filteruser_has_capinc\base.php:31
filtermanage_wp_block_posts_columnsinc\base.php:32
actionmanage_posts_custom_columninc\base.php:33
actionmanage_pages_custom_columninc\base.php:34
filtermanage_wp_block_posts_columnsinc\base.php:36
actionmanage_wp_block_posts_custom_columninc\base.php:37
filterposts_whereinc\base.php:135
Maintenance & Trust

Fabrica Synced Pattern Instances Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 14, 2024
PHP min version5.6
Downloads6K

Community Trust

Rating100/100
Number of ratings6
Active installs300
Developer Profile

Fabrica Synced Pattern Instances Developer Profile

Yes We Work

3 plugins · 380 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
12 days
View full developer profile
Detection Fingerprints

How We Detect Fabrica Synced Pattern Instances

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fabrica-reusable-block-instances/css/admin.css/wp-content/plugins/fabrica-reusable-block-instances/js/admin.js
Script Paths
/wp-content/plugins/fabrica-reusable-block-instances/js/admin.js
Version Parameters
fabrica-reusable-block-instances/css/admin.css?ver=fabrica-reusable-block-instances/js/admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
class="post_type_page"
JS Globals
fabricaReusableBlockInstances
FAQ

Frequently Asked Questions about Fabrica Synced Pattern Instances