Find My Blocks – Locate blocks on your site Security & Risk Analysis

wordpress.org/plugins/find-my-blocks

Find My Blocks will search and list all the blocks used across your WordPress site.

4K active installs v4.0.3 PHP 7.4+ WP 5.0+ Updated Nov 13, 2024
blocksfindgutenberglocatorsearch-blocks
92
A · Safe
CVEs total1
Unpatched0
Last CVESep 15, 2021
Safety Verdict

Is Find My Blocks – Locate blocks on your site Safe to Use in 2026?

Generally Safe

Score 92/100

Find My Blocks – Locate blocks on your site has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Sep 15, 2021Updated 1yr ago
Risk Assessment

The plugin "find-my-blocks" v4.0.3 exhibits a generally good security posture, with a significant emphasis on secure coding practices. The static analysis reveals no dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. The absence of file operations and external HTTP requests further mitigates common attack vectors. Furthermore, the single REST API route and the single entry point are protected by capability checks, and there are no unauthenticated AJAX handlers or shortcodes, indicating a well-defined and secured attack surface. The taint analysis also shows no critical or high severity flows with unsanitized paths. However, the plugin's vulnerability history, which includes one known CVE classified as medium in the past, specifically related to Missing Authorization, suggests that while current code appears more robust, past issues indicate a potential area of concern. This suggests that developers are actively addressing vulnerabilities, but the presence of a past authorization issue warrants continued vigilance for any such findings in the future. Overall, the plugin demonstrates strengths in secure coding and attack surface management, but the historical vulnerability should be a reminder to maintain a proactive security approach.

Key Concerns

  • Previous medium severity CVE for Missing Authorization
Vulnerabilities
1

Find My Blocks – Locate blocks on your site Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2021-24677medium · 5.3Missing Authorization

Find My Blocks < 3.4.0 - Sensitive Information Disclosure

Sep 15, 2021 Patched in 3.4.0 (860d)
Code Analysis
Analyzed Mar 16, 2026

Find My Blocks – Locate blocks on your site Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Find My Blocks – Locate blocks on your site Attack Surface

Entry Points1
Unprotected0

REST API Routes 1

GET/wp-json/find-my-blocks/v1searchinc\register-route.php:20
WordPress Hooks 3
actionadmin_enqueue_scriptsinc\enqueue.php:72
actionrest_api_initinc\register-route.php:33
actionadmin_menuinc\settings-page.php:27
Maintenance & Trust

Find My Blocks – Locate blocks on your site Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 13, 2024
PHP min version7.4
Downloads118K

Community Trust

Rating96/100
Number of ratings50
Active installs4K
Developer Profile

Find My Blocks – Locate blocks on your site Developer Profile

Morgan Hvidt

5 plugins · 9K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
860 days
View full developer profile
Detection Fingerprints

How We Detect Find My Blocks – Locate blocks on your site

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/find-my-blocks/assets/js/find-my-blocks.js/wp-content/plugins/find-my-blocks/assets/js/main.css/wp-content/plugins/find-my-blocks/assets/css/find-my-blocks.css
Script Paths
/wp-content/plugins/find-my-blocks/assets/js/find-my-blocks.js

HTML / DOM Fingerprints

Data Attributes
data-block
JS Globals
fmbGlobal
REST Endpoints
/wp-json/find-my-blocks/v1/search
FAQ

Frequently Asked Questions about Find My Blocks – Locate blocks on your site