
Fast BlockControl Security & Risk Analysis
wordpress.org/plugins/fast-blockcontrolEasily Control The Visibility Of Your Gutenberg Blocks With Tags
Is Fast BlockControl Safe to Use in 2026?
Generally Safe
Score 85/100Fast BlockControl has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "fast-blockcontrol" v1.2.2 plugin exhibits a mixed security posture. On the positive side, there are no recorded vulnerabilities (CVEs) in its history, and the static analysis shows no dangerous functions, file operations, external HTTP requests, or critical taint analysis findings. Furthermore, all output appears to be properly escaped, and there are no bundled libraries that could introduce outdated components. This suggests a degree of care in its development regarding common vulnerability vectors.
However, significant concerns arise from the identified attack surface. The plugin exposes one REST API route that lacks permission callbacks, meaning it's accessible without proper authentication. This is a critical oversight, as an attacker could potentially interact with this endpoint in unintended ways, leading to various security issues depending on its functionality. The absence of nonce checks and capability checks on this entry point exacerbates the risk. The presence of a SQL query that does not use prepared statements is another weakness, potentially opening the door to SQL injection vulnerabilities if user input is not meticulously sanitized before being used in the query.
While the lack of historical vulnerabilities is reassuring, it doesn't negate the risks identified in the current code. The high number of unprotected entry points, particularly the REST API route, coupled with the raw SQL query, represents the most immediate threats. The plugin has strengths in output sanitization and avoiding common pitfalls like dangerous functions, but the identified unauthenticated REST API endpoint and the un-prepared SQL query are significant security weaknesses that need immediate attention.
Key Concerns
- REST API route without permission callbacks
- SQL query without prepared statements
- No nonce checks
- No capability checks
Fast BlockControl Security Vulnerabilities
Fast BlockControl Code Analysis
SQL Query Safety
Fast BlockControl Attack Surface
REST API Routes 1
WordPress Hooks 6
Maintenance & Trust
Fast BlockControl Maintenance & Trust
Maintenance Signals
Community Trust
Fast BlockControl Alternatives
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Page Builder Gutenberg Blocks – CoBlocks
coblocks
CoBlocks is a suite of page builder WordPress blocks for Gutenberg, with 10+ new blocks and a true page builder experience with rows and columns.
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
otter-blocks
Quickly create WordPress pages with 20+ blocks, 100+ ready-to-import designs, and advanced editor extensions. It’s website building, Lego-style!
Fast BlockControl Developer Profile
14 plugins · 940 total installs
How We Detect Fast BlockControl
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fast-blockcontrol/dist/block.js/wp-content/plugins/fast-blockcontrol/dist/block.css/wp-content/plugins/fast-blockcontrol/dist/block.jsfast-blockcontrol/dist/block.js?ver=fast-blockcontrol/dist/block.css?ver=HTML / DOM Fingerprints
wp:/wp:data-showtagsdata-hidetags/wp-json/fasttag-gutenberg/v1/get-fast-tags