Cool Flipbox – Shortcode & Gutenberg Block Security & Risk Analysis

wordpress.org/plugins/flip-boxes

Show off your team members, staff, and employees in a visually appealing way. Make sure your team's profiles not only grab attention but also sti …

6K active installs v2.0.0 PHP 5.6+ WP 4.5+ Updated Feb 20, 2026
cool-flipboxflip-imagesflipboxflipbox-block
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 10, 2025
Safety Verdict

Is Cool Flipbox – Shortcode & Gutenberg Block Safe to Use in 2026?

Generally Safe

Score 99/100

Cool Flipbox – Shortcode & Gutenberg Block has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 10, 2025Updated 1mo ago
Risk Assessment

The flip-boxes plugin v2.0.0 demonstrates a generally good security posture with several strengths. The code analysis shows a commendable focus on security best practices, with all identified SQL queries utilizing prepared statements and a high percentage of outputs being properly escaped. The plugin also incorporates a good number of nonce and capability checks, indicating an awareness of common WordPress security vulnerabilities. The absence of critical or high-severity taint analysis findings further reinforces this positive outlook, suggesting that user-supplied data is generally handled securely.

However, a past medium-severity Cross-Site Scripting (XSS) vulnerability, though now patched, warrants attention. The fact that it was an XSS issue highlights the importance of continued vigilance in output escaping and input sanitization, even when current analysis shows high escape rates. The presence of external HTTP requests could also be a potential vector if not carefully implemented, and while not explicitly flagged as a risk, requires further investigation into their purpose and how they handle external data.

Overall, the plugin appears to be developed with security in mind, evidenced by its robust internal checks and clean static analysis results for the current version. The past vulnerability history, while concerning, is mitigated by its patched status. Continued monitoring for new vulnerabilities and careful review of any external interactions remain important for maintaining a strong security profile.

Key Concerns

  • Past medium severity XSS vulnerability
  • External HTTP requests (potential risk)
Vulnerabilities
1

Cool Flipbox – Shortcode & Gutenberg Block Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-32521medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Cool Flipbox – Shortcode & Gutenberg Block <= 1.8.3 - Reflected Cross-Site Scripting

Apr 10, 2025 Patched in 1.9.0 (12d)
Code Analysis
Analyzed Mar 16, 2026

Cool Flipbox – Shortcode & Gutenberg Block Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
36
408 escaped
Nonce Checks
5
Capability Checks
10
File Operations
1
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

92% escaped444 total outputs
Attack Surface

Cool Flipbox – Shortcode & Gutenberg Block Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 3

authwp_ajax_cmb2_oembed_handleradmin\CMB2\includes\CMB2_Ajax.php:55
noprivwp_ajax_cmb2_oembed_handleradmin\CMB2\includes\CMB2_Ajax.php:56
authwp_ajax_cfb_dismiss_noticeadmin\feedback\cfb-feedback-notice.php:21

Shortcodes 1

[flipboxes] includes\cfb-shortcode.php:20
WordPress Hooks 79
actionadmin_menuadmin\cfb-post-type.php:12
actionadmin_initadmin\cfb-post-type.php:13
actioninitadmin\cfb-post-type.php:21
actioncmb2_admin_initadmin\cfb-post-type.php:22
actioncmb2_admin_initadmin\cfb-post-type.php:23
actioncmb2_admin_initadmin\cfb-post-type.php:24
actioncmb2_admin_initadmin\cfb-post-type.php:25
filtermanage_edit-flipboxes_columnsadmin\cfb-post-type.php:26
actionmanage_flipboxes_posts_custom_columnadmin\cfb-post-type.php:27
actionadd_meta_boxesadmin\cfb-post-type.php:28
actioncmb2_render_fontawesome_iconadmin\CMB2\cmb2-fontawesome-picker.php:21
actioncmb2_sanitize_fontawesome_iconadmin\CMB2\cmb2-fontawesome-picker.php:22
filterwp_prepare_attachment_for_jsadmin\CMB2\includes\CMB2.php:1577
actionadmin_enqueue_scriptsadmin\CMB2\includes\CMB2.php:1594
actioncmb2_save_options-page_fieldsadmin\CMB2\includes\CMB2_Ajax.php:58
filterget_post_metadataadmin\CMB2\includes\CMB2_Ajax.php:151
filterupdate_post_metadataadmin\CMB2\includes\CMB2_Ajax.php:154
filtercmb2_show_onadmin\CMB2\includes\CMB2_Hookup.php:81
actionedit_form_topadmin\CMB2\includes\CMB2_Hookup.php:120
actionedit_form_before_permalinkadmin\CMB2\includes\CMB2_Hookup.php:124
actionedit_form_after_titleadmin\CMB2\includes\CMB2_Hookup.php:128
actionedit_form_after_editoradmin\CMB2\includes\CMB2_Hookup.php:132
actionadd_meta_boxesadmin\CMB2\includes\CMB2_Hookup.php:136
actionadd_meta_boxesadmin\CMB2\includes\CMB2_Hookup.php:139
actionadd_attachmentadmin\CMB2\includes\CMB2_Hookup.php:140
actionedit_attachmentadmin\CMB2\includes\CMB2_Hookup.php:141
actionsave_postadmin\CMB2\includes\CMB2_Hookup.php:142
actionpre_get_postsadmin\CMB2\includes\CMB2_Hookup.php:149
actionadd_meta_boxes_commentadmin\CMB2\includes\CMB2_Hookup.php:157
actionedit_commentadmin\CMB2\includes\CMB2_Hookup.php:158
filtermanage_edit-comments_columnsadmin\CMB2\includes\CMB2_Hookup.php:161
actionmanage_comments_custom_columnadmin\CMB2\includes\CMB2_Hookup.php:162
filtermanage_edit-comments_sortable_columnsadmin\CMB2\includes\CMB2_Hookup.php:163
actionpre_get_postsadmin\CMB2\includes\CMB2_Hookup.php:164
actionshow_user_profileadmin\CMB2\includes\CMB2_Hookup.php:173
actionedit_user_profileadmin\CMB2\includes\CMB2_Hookup.php:174
actionuser_new_formadmin\CMB2\includes\CMB2_Hookup.php:175
actionpersonal_options_updateadmin\CMB2\includes\CMB2_Hookup.php:177
actionedit_user_profile_updateadmin\CMB2\includes\CMB2_Hookup.php:178
actionuser_registeradmin\CMB2\includes\CMB2_Hookup.php:179
filtermanage_users_columnsadmin\CMB2\includes\CMB2_Hookup.php:182
filtermanage_users_custom_columnadmin\CMB2\includes\CMB2_Hookup.php:183
filtermanage_users_sortable_columnsadmin\CMB2\includes\CMB2_Hookup.php:184
actionpre_get_postsadmin\CMB2\includes\CMB2_Hookup.php:185
actionpre_get_postsadmin\CMB2\includes\CMB2_Hookup.php:231
actioncreated_termadmin\CMB2\includes\CMB2_Hookup.php:235
actionedited_termsadmin\CMB2\includes\CMB2_Hookup.php:236
actiondelete_termadmin\CMB2\includes\CMB2_Hookup.php:237
actioncmb2_do_oembedadmin\CMB2\includes\helper-functions.php:138
filteris_protected_metaadmin\CMB2\includes\rest-api\CMB2_REST.php:149
actioninitadmin\CMB2\init.php:82
actionadmin_enqueue_scriptsadmin\feedback\admin-feedback-form.php:48
actionadmin_headadmin\feedback\admin-feedback-form.php:49
actionadmin_noticesadmin\feedback\cfb-feedback-notice.php:19
actionadmin_enqueue_scriptsadmin\feedback\cfb-feedback-notice.php:20
actionplugins_loadedflipboxes.php:35
actionadmin_enqueue_scriptsflipboxes.php:36
actionactivated_pluginflipboxes.php:37
actionwp_headincludes\cfb-block\inc\class-blocks-css.php:38
actioninitincludes\cfb-block\inc\class-cfb-block.php:41
actioninitincludes\cfb-block\inc\class-cfb-css-base.php:61
actioninitincludes\cfb-block\inc\class-registration.php:34
actionenqueue_block_editor_assetsincludes\cfb-block\inc\class-registration.php:35
actionenqueue_block_assetsincludes\cfb-block\inc\class-registration.php:36
actionwpincludes\cfb-block\inc\css\class-cfb-block-frontend.php:43
actionwp_enqueue_scriptsincludes\cfb-block\inc\css\class-cfb-block-frontend.php:44
actionwp_enqueue_scriptsincludes\cfb-block\inc\css\class-cfb-block-frontend.php:45
actionwp_headincludes\cfb-block\inc\css\class-cfb-block-frontend.php:46
actionwp_footerincludes\cfb-block\inc\css\class-cfb-block-frontend.php:47
filterthe_contentincludes\cfb-block\inc\css\class-cfb-block-frontend.php:162
actionwp_footerincludes\cfb-block\inc\css\class-cfb-block-frontend.php:199
actionwp_footerincludes\cfb-block\inc\css\class-cfb-block-frontend.php:215
actionwp_footerincludes\cfb-block\inc\css\class-cfb-block-frontend.php:248
actionwp_footerincludes\cfb-block\inc\css\class-cfb-block-frontend.php:265
actionrest_api_initincludes\cfb-block\inc\css\class-cfb-style-handler.php:28
actionrest_api_initincludes\cfb-block\inc\css\class-cfb-style-handler.php:30
actionbefore_delete_postincludes\cfb-block\inc\css\class-cfb-style-handler.php:32
actionwp_enqueue_scriptsincludes\cfb-shortcode.php:22
actionadmin_enqueue_scriptsincludes\cfb-shortcode.php:23
Maintenance & Trust

Cool Flipbox – Shortcode & Gutenberg Block Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 20, 2026
PHP min version5.6
Downloads113K

Community Trust

Rating96/100
Number of ratings103
Active installs6K
Developer Profile

Cool Flipbox – Shortcode & Gutenberg Block Developer Profile

CoolHappy

12 plugins · 210K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
203 days
View full developer profile
Detection Fingerprints

How We Detect Cool Flipbox – Shortcode & Gutenberg Block

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/flip-boxes/admin/feedback/admin-feedback-form.php/wp-content/plugins/flip-boxes/includes/cfb-functions.php/wp-content/plugins/flip-boxes/includes/cfb-shortcode.php/wp-content/plugins/flip-boxes/includes/cfb-block/inc/class-cfb-block.php/wp-content/plugins/flip-boxes/admin/cfb-post-type.php/wp-content/plugins/flip-boxes/admin/feedback/cfb-feedback-notice.php/wp-content/plugins/flip-boxes/admin/CMB2/init.php/wp-content/plugins/flip-boxes/admin/CMB2/cmb2-fontawesome-picker.php
Version Parameters
flip-boxes/style.css?ver=flip-boxes/js/flip-boxes-admin.js?ver=flip-boxes/js/flip-boxes-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
cfb-flip-box-wrapcfb-flip-boxcfb-flip-box-innercfb-flip-box-frontcfb-flip-box-backcfb-flip-box-content
HTML Comments
<!-- Cool Plugins Flipbox Start --><!-- Cool Plugins Flipbox End -->
Data Attributes
data-flipbox-iddata-effectdata-duration
JS Globals
cfb_flipbox_options
Shortcode Output
[flipbox [flipbox]
FAQ

Frequently Asked Questions about Cool Flipbox – Shortcode & Gutenberg Block