Flex Guten – Multile Blocks Security & Risk Analysis

wordpress.org/plugins/flex-guten

Flex Guten is a multipurpose block editor plugin with Pinterest, post grid, and testimonial blocks.

400 active installs v1.2.6 PHP 5.7+ WP 5.7+ Updated Aug 7, 2025
amazongridlatest-postpinterestpost
99
A · Safe
CVEs total1
Unpatched0
Last CVEAug 5, 2025
Download
Safety Verdict

Is Flex Guten – Multile Blocks Safe to Use in 2026?

Generally Safe

Score 99/100

Flex Guten – Multile Blocks has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Aug 5, 2025Updated 8mo ago
Risk Assessment

The static analysis of flex-guten v1.2.6 reveals a plugin with an exceptionally small attack surface and adherence to good coding practices in critical areas. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, meaning there are no direct entry points for attackers to exploit. The code also demonstrates proper handling of SQL queries, output escaping, and avoids dangerous functions, file operations, and external HTTP requests. However, the complete absence of nonce checks and capability checks across all entry points is a significant concern, as it implies a lack of authorization enforcement. This could allow any user, regardless of their role or permissions, to trigger plugin functionalities if any were present. The plugin's vulnerability history, although showing one past medium severity Cross-Site Scripting (XSS) vulnerability, indicates that the issue is no longer present in this version, which is positive. Despite the clean code signals in the current version, the lack of robust authorization checks presents a latent risk that could be exploited if new entry points are introduced or existing ones are made accessible. Overall, the plugin exhibits strong technical implementation in terms of secure coding for SQL and output, but the lack of authorization checks across its minimal entry points is a notable weakness.

Key Concerns

  • Missing Nonce Checks on Entry Points
  • Missing Capability Checks on Entry Points
Vulnerabilities
1

Flex Guten – Multile Blocks Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-6256medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Flex Guten <= 1.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via thumbnailHoverEffect Parameter

Aug 5, 2025 Patched in 1.2.6 (6d)
Code Analysis
Analyzed Mar 16, 2026

Flex Guten – Multile Blocks Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

Flex Guten – Multile Blocks Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionwp_enqueue_scriptsincludes\Assets.php:10
actionadmin_enqueue_scriptsincludes\Assets.php:11
actioninitincludes\Blocks\BlockRegister\BlockRegister.php:10
actioninitincludes\Blocks\BlockStyle\PostGridOne\PostGridOne.php:11
filterblock_categoriesplugin.php:43
filterblock_categories_allplugin.php:45
actionenqueue_block_assetsplugin.php:51
filterclean_urlplugin.php:52
Maintenance & Trust

Flex Guten – Multile Blocks Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 7, 2025
PHP min version5.7
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs400
Developer Profile

Flex Guten – Multile Blocks Developer Profile

Drag WP

5 plugins · 1K total installs

95
trust score
Avg Security Score
93/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect Flex Guten – Multile Blocks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/flex-guten/includes/assets/js/plugin.js/wp-content/plugins/flex-guten/includes/assets/js/rater.min.js/wp-content/plugins/flex-guten/includes/assets/css/main.css/wp-content/plugins/flex-guten/includes/assets/fonts/merriweather.css/wp-content/plugins/flex-guten/includes/assets/fonts/proxima-nova-2.css/wp-content/plugins/flex-guten/includes/assets/fonts/sharp-sans.css/wp-content/plugins/flex-guten/includes/assets/fonts/nunito.css
Script Paths
//assets.pinterest.com/js/pinit.js
Version Parameters
flexguten-plugin-script?ver=flexguten-rater-script?ver=flexguten-pinit-script?ver=flexguten-plugin-style?ver=flexguten-merriweather-font?ver=flexguten-proximanova-font?ver=flexguten-sharpsans-font?ver=flexguten-nunito-font?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Flex Guten – Multile Blocks