GTG Product Blocks Security & Risk Analysis

wordpress.org/plugins/gtg-product-blocks

This GTG Product Block is one of the most powerful plugin for Gutenberg that is compatible with WooCommerce to display your products on posts and page …

10 active installs v1.0.0 PHP 7.2+ WP 5.3+ Updated Dec 3, 2020
blocksgutenbergproductswoo-commercewoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GTG Product Blocks Safe to Use in 2026?

Generally Safe

Score 85/100

GTG Product Blocks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

Based on the static analysis and vulnerability history provided, the 'gtg-product-blocks' plugin version 1.0.0 exhibits an exceptionally strong security posture. The plugin demonstrates adherence to best practices by having no identified attack surface points, zero dangerous functions, and 100% of its SQL queries utilizing prepared statements. Furthermore, all identified output operations are properly escaped, and there are no file operations or external HTTP requests, significantly reducing the potential for common web vulnerabilities.

The absence of any taint analysis findings, including unsanitized paths or critical/high severity flows, is a particularly positive indicator of secure coding. The plugin's vulnerability history is also clean, with no known CVEs or past vulnerabilities recorded. This suggests a proactive approach to security by the developers or a lack of past exposure to sophisticated attacks.

While the plugin appears very secure in its current state, the complete absence of nonce and capability checks across its (non-existent) entry points, along with zero AJAX handlers and REST API routes, is noteworthy. Although this contributes to a zero attack surface, it means that if any future functionalities are added without proper authorization checks, the plugin could become vulnerable. However, given the current state, the risk is extremely low, and the plugin's design for version 1.0.0 is highly commendable.

Vulnerabilities
None known

GTG Product Blocks Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

GTG Product Blocks Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
13 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped13 total outputs
Attack Surface

GTG Product Blocks Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionplugins_loadedgtg-product-blocks.php:26
actionadmin_noticesgtg-product-blocks.php:36
filterrest_request_after_callbacksinc\BlockTypes\ProductLookBook.php:46
actioninitinc\class-block-library.php:39
actioninitinc\class-block-library.php:40
actionenqueue_block_editor_assetsinc\class-block-library.php:41
filterregister_block_type_argsinc\class-block-library.php:42
filterregister_block_type_argsinc\class-block-library.php:43
actionplugins_loadedinc\plugin.php:33
Maintenance & Trust

GTG Product Blocks Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedDec 3, 2020
PHP min version7.2
Downloads962

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

GTG Product Blocks Developer Profile

wpopal

19 plugins · 3K total installs

81
trust score
Avg Security Score
90/100
Avg Patch Time
50 days
View full developer profile
Detection Fingerprints

How We Detect GTG Product Blocks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gtg-product-blocks/build/editor.js/wp-content/plugins/gtg-product-blocks/build/gutengeek.js/wp-content/plugins/gtg-product-blocks/assets/libs/popperjs/popper.min.js/wp-content/plugins/gtg-product-blocks/assets/libs/tippyjs/tippy-bundle.umd.min.js/wp-content/plugins/gtg-product-blocks/assets/libs/tippyjs/tippy.css/wp-content/plugins/gtg-product-blocks/build/product-lookbook.js/wp-content/plugins/gtg-product-blocks/build/product-lookbook.css/wp-content/plugins/gtg-product-blocks/build/product-lookbook-frontend.js+1 more
Script Paths
/wp-content/plugins/gtg-product-blocks/build/editor.js/wp-content/plugins/gtg-product-blocks/build/gutengeek.js/wp-content/plugins/gtg-product-blocks/assets/libs/popperjs/popper.min.js/wp-content/plugins/gtg-product-blocks/assets/libs/tippyjs/tippy-bundle.umd.min.js/wp-content/plugins/gtg-product-blocks/build/product-lookbook.js/wp-content/plugins/gtg-product-blocks/build/product-lookbook-frontend.js+1 more
Version Parameters
gtg-product-blocks/build/editor.js?ver=gtg-product-blocks/build/gutengeek.js?ver=gtg-product-blocks/assets/libs/popperjs/popper.min.js?ver=gtg-product-blocks/assets/libs/tippyjs/tippy-bundle.umd.min.js?ver=gtg-product-blocks/assets/libs/tippyjs/tippy.css?ver=gtg-product-blocks/build/product-lookbook.js?ver=gtg-product-blocks/build/product-lookbook.css?ver=gtg-product-blocks/build/product-lookbook-frontend.js?ver=gtg-product-blocks/build/featured-category.js?ver=

HTML / DOM Fingerprints

Data Attributes
gutengeekCustomCSSgutengeekAnimationblockAnimationgutengeekResponsive
JS Globals
gpb_woo_loadedgpb_woo_notice
FAQ

Frequently Asked Questions about GTG Product Blocks