Gotham Block Extra Light Security & Risk Analysis

wordpress.org/plugins/gotham-block-extra-light

This plugin detects if the user's browser has AdBlock software activated and displays a popup if this is the case (screenshot 1).

50 active installs v1.6.0 PHP 7.4.0+ WP 6.0+ Updated Jan 13, 2026
adblockadsblock-adblockdetect-adblock
98
A · Safe
CVEs total2
Unpatched0
Last CVEJan 13, 2026
Download
Safety Verdict

Is Gotham Block Extra Light Safe to Use in 2026?

Generally Safe

Score 98/100

Gotham Block Extra Light has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Jan 13, 2026Updated 2mo ago
Risk Assessment

The "gotham-block-extra-light" v1.6.0 plugin presents a mixed security posture. On the positive side, the static analysis shows a very limited attack surface, with no unprotected AJAX handlers or REST API routes, and all SQL queries utilizing prepared statements. The presence of capability checks is also a good sign. However, concerns arise from the output escaping, where only 42% of outputs are properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully.

The vulnerability history is a significant area of concern. With two known medium-severity CVEs, specifically related to Cross-Site Scripting and Path Traversal, the plugin has a history of exploitable flaws. Although there are currently no unpatched vulnerabilities from this history, the past issues suggest a pattern of imperfect input sanitization and path handling, which aligns with the observed low percentage of properly escaped outputs. The recency of the last known vulnerability (2026-01-13) is concerning, though it might indicate an outdated vulnerability database entry rather than a current threat.

In conclusion, while the plugin demonstrates some good security practices like secure SQL usage and a small attack surface, the historical medium vulnerabilities and the high proportion of unescaped output introduce notable risks. Developers should prioritize addressing the output escaping issues to mitigate XSS risks and remain vigilant about any future vulnerabilities related to path handling.

Key Concerns

  • Medium severity vulnerabilities in history
  • Low percentage of properly escaped output
  • Medium severity XSS vulnerability history
  • Medium severity Path Traversal vulnerability history
Vulnerabilities
2

Gotham Block Extra Light Security Vulnerabilities

CVEs by Year

2 CVEs in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-15021medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Gotham Block Extra Light <= 1.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings

Jan 13, 2026 Patched in 1.6.0 (2d)
CVE-2025-15020medium · 6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Gotham Block Extra Light <= 1.5.0 - Authenticated (Contributor+) Arbitrary File Read via 'ghostban' Shortcode

Jan 13, 2026 Patched in 1.6.0 (2d)
Code Analysis
Analyzed Mar 16, 2026

Gotham Block Extra Light Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
63
45 escaped
Nonce Checks
0
Capability Checks
2
File Operations
3
External Requests
1
Bundled Libraries
0

Output Escaping

42% escaped108 total outputs
Attack Surface

Gotham Block Extra Light Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ghostban] premium\ghostban.php:130
WordPress Hooks 13
actionwp_footergothamblock.php:222
actioninitgothamblock.php:227
actionwp_footergothamblock.php:245
actionadmin_initgothamblock.php:329
actionadmin_enqueue_scriptsgothamblock.php:340
actionadmin_menugothamblock.php:347
actionadmin_enqueue_scriptsgothamblock.php:385
actionwp_enqueue_scriptsgothamblock.php:644
filterrobots_txtgothamblock.php:658
actionwidgets_initgothamblock.php:670
filtermce_external_pluginsgothamblock.php:682
filtermce_buttonsgothamblock.php:683
actionadmin_initgothamblock.php:692
Maintenance & Trust

Gotham Block Extra Light Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 13, 2026
PHP min version7.4.0
Downloads7K

Community Trust

Rating64/100
Number of ratings11
Active installs50
Developer Profile

Gotham Block Extra Light Developer Profile

Kapsule Corp

7 plugins · 200 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
2 days
View full developer profile
Detection Fingerprints

How We Detect Gotham Block Extra Light

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gotham-block-extra-light/stop.png/wp-content/plugins/gotham-block-extra-light/ok.png

HTML / DOM Fingerprints

CSS Classes
gothamadsgtmab_leviator
HTML Comments
Version avec Ads.jsPlugin ULTRA Léger pour informer tout simplement vos visiteurs que les bloqueurs de publicité tuent la viabilité de votre site, et les invite à les désactiver.
Data Attributes
id='gothamadblock_msg'id='gothamadblock_overlayh_n'id='gtab_mehn'onclick='gothamadblock_myClosePop()'onclick='gothamadblock_myClosePopSSJ()'
JS Globals
gothamadblock_last_visit_timegothamadblock_myClosePopgothamadblock_myClosePopSSJgothamBatAdblock
FAQ

Frequently Asked Questions about Gotham Block Extra Light