
Gotham Block Extra Light Security & Risk Analysis
wordpress.org/plugins/gotham-block-extra-lightThis plugin detects if the user's browser has AdBlock software activated and displays a popup if this is the case (screenshot 1).
Is Gotham Block Extra Light Safe to Use in 2026?
Generally Safe
Score 98/100Gotham Block Extra Light has a strong security track record. Known vulnerabilities have been patched promptly.
The "gotham-block-extra-light" v1.6.0 plugin presents a mixed security posture. On the positive side, the static analysis shows a very limited attack surface, with no unprotected AJAX handlers or REST API routes, and all SQL queries utilizing prepared statements. The presence of capability checks is also a good sign. However, concerns arise from the output escaping, where only 42% of outputs are properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully.
The vulnerability history is a significant area of concern. With two known medium-severity CVEs, specifically related to Cross-Site Scripting and Path Traversal, the plugin has a history of exploitable flaws. Although there are currently no unpatched vulnerabilities from this history, the past issues suggest a pattern of imperfect input sanitization and path handling, which aligns with the observed low percentage of properly escaped outputs. The recency of the last known vulnerability (2026-01-13) is concerning, though it might indicate an outdated vulnerability database entry rather than a current threat.
In conclusion, while the plugin demonstrates some good security practices like secure SQL usage and a small attack surface, the historical medium vulnerabilities and the high proportion of unescaped output introduce notable risks. Developers should prioritize addressing the output escaping issues to mitigate XSS risks and remain vigilant about any future vulnerabilities related to path handling.
Key Concerns
- Medium severity vulnerabilities in history
- Low percentage of properly escaped output
- Medium severity XSS vulnerability history
- Medium severity Path Traversal vulnerability history
Gotham Block Extra Light Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Gotham Block Extra Light <= 1.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings
Gotham Block Extra Light <= 1.5.0 - Authenticated (Contributor+) Arbitrary File Read via 'ghostban' Shortcode
Gotham Block Extra Light Code Analysis
Output Escaping
Gotham Block Extra Light Attack Surface
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
Gotham Block Extra Light Maintenance & Trust
Maintenance Signals
Community Trust
Gotham Block Extra Light Alternatives
NS AdBlock Blocker
ns-adblock-blocker
Allows you to lock site display to users with ad Blockers installed and increase your earns.
Admiral Adblock Analytics
admiral-adblock-suite
Detect adblock, measure adblock and block adblock on your site. Help users of adblock plus, ublock and other adblockers whitelist your site.
Clarity – Ad blocker for WordPress
clarity-ad-blocker
Clarity is an ad blocker for your WordPress admin. It hides obtrusive plugin and theme notifications asking you to pay for upgraded version or to col …
CHP Ads Block Detector
chp-ads-block-detector
Block Ads Blocker Extensions and Increase your revenue by using Ads Blocker Detector Plugin
AdUnblocker
adunblocker
This plugin detects if Google AdSense (or any other ad network) ads are not running on your site. Ads are usually blocked by ad-blockers (eg AdBlock, …
Gotham Block Extra Light Developer Profile
7 plugins · 200 total installs
How We Detect Gotham Block Extra Light
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gotham-block-extra-light/stop.png/wp-content/plugins/gotham-block-extra-light/ok.pngHTML / DOM Fingerprints
gothamadsgtmab_leviatorVersion avec Ads.jsPlugin ULTRA Léger pour informer tout simplement vos visiteurs que les bloqueurs de publicité tuent la viabilité de votre site, et les invite à les désactiver.id='gothamadblock_msg'id='gothamadblock_overlayh_n'id='gtab_mehn'onclick='gothamadblock_myClosePop()'onclick='gothamadblock_myClosePopSSJ()'gothamadblock_last_visit_timegothamadblock_myClosePopgothamadblock_myClosePopSSJgothamBatAdblock