Gutenify – Visual Site Builder Blocks & Site Templates. Security & Risk Analysis

wordpress.org/plugins/gutenify

Gutenify is a free WordPress plugin which allows you to add different block effortlessly in your site.

5K active installs v1.6.2 PHP 5.5+ WP 6.4+ Updated Mar 18, 2026
blockblockseditorgutenberggutenberg-blocks
67
C · Use Caution
CVEs total5
Unpatched1
Last CVENov 17, 2025
Safety Verdict

Is Gutenify – Visual Site Builder Blocks & Site Templates. Safe to Use in 2026?

Use With Caution

Score 67/100

Gutenify – Visual Site Builder Blocks & Site Templates. has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

5 known CVEs 1 unpatched Last CVE: Nov 17, 2025Updated 2mo ago
Risk Assessment

The Gutenify plugin, version 1.6.1, presents a mixed security posture. On one hand, the static analysis reveals a clean attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected. Furthermore, all detected SQL queries are properly prepared, and a significant majority of output is correctly escaped, indicating good practices in these areas. The absence of critical taint flows and dangerous functions is also a positive sign. However, the plugin exhibits several concerning indicators. Notably, there are no nonce checks implemented, which is a significant omission for any plugin that handles user input or performs actions. The presence of 8 external HTTP requests without explicit mention of their security context is another area to monitor, as these could potentially be exploited. The plugin also lacks capability checks on some entry points, which, combined with the absence of nonce checks, could allow unauthorized users to perform actions. The vulnerability history is a major red flag. With a total of 5 known CVEs, including one that remains unpatched, and a significant number of high and medium severity vulnerabilities in the past, this plugin has a history of being a security risk. The common vulnerability types like Cross-site Scripting and PHP Remote File Inclusion, along with exposure of sensitive information, suggest recurring issues with input sanitization and access control. The last recorded vulnerability being recent also suggests ongoing security challenges. Therefore, while some code practices are sound, the historical vulnerability record and the lack of critical security checks like nonce verification warrant a high degree of caution.

Key Concerns

  • Unpatched CVE
  • High severity CVEs
  • Medium severity CVEs
  • No nonce checks
  • External HTTP requests
  • Capability checks are low
  • Output escaping is not 100%
Vulnerabilities
5 published

Gutenify – Visual Site Builder Blocks & Site Templates. Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
4 CVEs in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

High
2
Medium
3

5 total CVEs

CVE-2025-8605medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Gutenify - Visual Site Builder Blocks & Site Templates <= 1.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Count Up block

Nov 17, 2025Unpatched
CVE-2025-53324high · 7.2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Gutenify <= 1.5.7 - Unauthenticated Stored Cross-Site Scripting

Sep 23, 2025 Patched in 1.5.8 (22d)
CVE-2025-53326high · 8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Gutenify <= 1.5.4 - Unauthenticated Local File Inclusion

Aug 26, 2025 Patched in 1.5.5 (28d)
CVE-2025-32168medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Gutenify <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 4, 2025 Patched in 1.5.8 (194d)
CVE-2024-35165medium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

Gutenify <= 1.4.0 - Unauthenticated Sensitive Information Exposure

May 10, 2024 Patched in 1.4.1 (6d)
Code Analysis
Analyzed Mar 16, 2026

Gutenify – Visual Site Builder Blocks & Site Templates. Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
34 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
8
Bundled Libraries
0

Output Escaping

83% escaped41 total outputs
Attack Surface

Gutenify – Visual Site Builder Blocks & Site Templates. Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 31
actioninitcore\inc\admin\class-demo-importer-v2.php:34
actionadmin_menucore\inc\admin\class-menu.php:25
actioninitcore\inc\admin\class-menu.php:26
actioninitcore\inc\admin\class-register-templates-post-type.php:27
actionenqueue_block_assetscore\inc\blocks\class-block-assets.php:35
actionwp_enqueue_scriptscore\inc\blocks\class-block-assets.php:36
actionenqueue_block_editor_assetscore\inc\blocks\class-block-editor-assets.php:34
actionwpcore\inc\blocks\class-block-inline-styles.php:10
actionwp_enqueue_scriptscore\inc\blocks\class-block-inline-styles.php:11
filterrender_blockcore\inc\blocks\class-block-inline-styles.php:15
filterblock_categories_allcore\inc\blocks\class-blocks-categories.php:29
filterrender_blockcore\inc\blocks\class-dynamic-block-classname.php:28
actionuse_block_editor_for_post_typecore\inc\blocks\class-editor-control.php:27
filtergutenify_skip_gutenburg_post_typecore\inc\blocks\class-editor-control.php:30
actionblock_type_metadatacore\inc\blocks\class-extend-attributes.php:26
filterwpforms_gutenberg_form_selector_attributescore\inc\blocks\class-fix-third-party-block-issues.php:47
filtergutenify_render_blockcore\inc\blocks\class-slider-blocks.php:8
actioninitcore\inc\class-assets.php:9
actionwp_enqueue_scriptscore\inc\class-assets.php:10
actionimport_endcore\inc\depricated\demo-importer.php:25
filterwp_theme_json_data_themecore\inc\depricated\helpers\typography-helpers.php:6948
actionwp_enqueue_scriptscore\inc\depricated\styles.php:108
actionwp_headcore\inc\frontend\class-global-code.php:49
actionwp_body_opencore\inc\frontend\class-global-code.php:50
actionwp_footercore\inc\frontend\class-global-code.php:51
actionenqueue_block_assetscore\inc\helpers\class-typography-helpers.php:28
filterwp_theme_json_data_usercore\inc\helpers\class-typography-helpers.php:31
filterblock_editor_settings_allcore\inc\helpers\helpers.php:49
actionrest_api_initcore\inc\rest-api\class-rest-demo-importer-v2.php:16
actionrest_api_initcore\inc\rest-api\class-rest.php:36
filtergutenify_plugin_constantsgutenify.php:82
Maintenance & Trust

Gutenify – Visual Site Builder Blocks & Site Templates. Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 18, 2026
PHP min version5.5
Downloads259K

Community Trust

Rating90/100
Number of ratings11
Active installs5K
Developer Profile

Gutenify – Visual Site Builder Blocks & Site Templates. Developer Profile

CodeYatri

54 plugins · 18K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
63 days
View full developer profile
Detection Fingerprints

How We Detect Gutenify – Visual Site Builder Blocks & Site Templates.

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gutenify/assets/css/gutenify-style.css/wp-content/plugins/gutenify/assets/css/gutenify-block.css/wp-content/plugins/gutenify/assets/css/gutenify-free.css/wp-content/plugins/gutenify/assets/css/gutenify-editor.css
Script Paths
/wp-content/plugins/gutenify/assets/js/gutenify-block.js/wp-content/plugins/gutenify/assets/js/gutenify-free.js
Version Parameters
gutenify/assets/css/gutenify-style.css?ver=gutenify/assets/css/gutenify-block.css?ver=gutenify/assets/css/gutenify-free.css?ver=gutenify/assets/css/gutenify-editor.css?ver=gutenify/assets/js/gutenify-block.js?ver=gutenify/assets/js/gutenify-free.js?ver=

HTML / DOM Fingerprints

CSS Classes
gutenify-blockgutenify-free-block
HTML Comments
Copyright (c) 2023 GutenifyLicensed under the GPLv2 or later.https://www.gnu.org/licenses/gpl-2.0.html
Data Attributes
data-block-name="gutenify/gutenify-block"data-block-name="gutenify/gutenify-free-block"
JS Globals
gutenify_editor_data
FAQ

Frequently Asked Questions about Gutenify – Visual Site Builder Blocks & Site Templates.