Gutenium Blocks Security & Risk Analysis

wordpress.org/plugins/gutenium

The gutenium block enhances content creation with advanced features, layouts, and customization options for dynamic and engaging blogs.

0 active installs v1.1.7 PHP 7.0+ WP 5.7+ Updated Unknown
blockgutenberg-blockgutenium-blockspage-builder
79
B · Generally Safe
CVEs total1
Unpatched1
Last CVENov 8, 2024
Download
Safety Verdict

Is Gutenium Blocks Safe to Use in 2026?

Mostly Safe

Score 79/100

Gutenium Blocks is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Nov 8, 2024
Risk Assessment

The Gutenium plugin v1.1.7 exhibits a generally strong security posture, particularly in its handling of SQL queries and output escaping, with nearly all outputs being properly sanitized. The plugin demonstrates good practice by implementing nonce and capability checks on its AJAX handlers and REST API routes, which significantly reduces the risk of common web vulnerabilities. The static analysis also reveals a minimal attack surface, with no identified shortcodes, cron events, or REST API routes exposed without proper authentication or permission callbacks.

However, the presence of one unpatched medium-severity CVE, specifically related to Cross-Site Scripting (XSS), is a significant concern. While the static analysis did not reveal any immediate XSS vulnerabilities in the current version, this historical vulnerability indicates a potential weakness in how the plugin handles user-provided data. The plugin also makes three external HTTP requests, which could be a vector for supply chain attacks if the external services are compromised, although no specific vulnerabilities are indicated by the provided data.

In conclusion, while Gutenium v1.1.7 adheres to many security best practices, the lingering unpatched XSS vulnerability is a critical risk that needs immediate attention. Addressing this historical issue will significantly improve the plugin's overall security. The limited attack surface and robust input/output sanitization in the current code are positive indicators, but the past vulnerability necessitates caution.

Key Concerns

  • Unpatched medium severity CVE (XSS)
Vulnerabilities
1

Gutenium Blocks Security Vulnerabilities

CVEs by Year

1 CVE in 2024 · unpatched
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-51869medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Gutenium Blocks <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 8, 2024Unpatched
Code Analysis
Analyzed Mar 17, 2026

Gutenium Blocks Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
570 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

99% escaped577 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
gutnm_plugin_function_for_datas_callback (includes\admin\index.php:45)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Gutenium Blocks Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_gutnm_save_settingsincludes\admin\index.php:66
WordPress Hooks 17
actionadmin_noticesgutenium-blocks.php:46
actionadmin_noticesgutenium-blocks.php:48
actionadmin_noticesgutenium-blocks.php:50
actionplugins_loadedgutenium-blocks.php:54
filterplugin_action_linksgutenium-blocks.php:56
actionadmin_menuincludes\admin\index.php:63
actionadmin_enqueue_scriptsincludes\admin\index.php:64
actionadmin_noticesincludes\admin-notice.php:13
actionadmin_post_handle_gutnm_email_subscriptionincludes\admin-notice.php:14
actioninitincludes\blocks-loader.php:26
filterblock_categories_allincludes\blocks-loader.php:30
filterblock_categoriesincludes\blocks-loader.php:32
filterrender_blockincludes\blocks-loader.php:36
actionenqueue_block_editor_assetsincludes\blocks-loader.php:39
actionenqueue_block_assetsincludes\blocks-loader.php:42
filtermime_typesincludes\blocks-loader.php:45
filterwp_check_filetype_and_extincludes\blocks-loader.php:47
Maintenance & Trust

Gutenium Blocks Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Gutenium Blocks Developer Profile

Best WP Developer

11 plugins · 720 total installs

95
trust score
Avg Security Score
93/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Gutenium Blocks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gutenium/includes/admin/assets/ajax-save.js/wp-content/plugins/gutenium/includes/admin/assets/gutnm-dashboard.css/wp-content/plugins/gutenium/includes/admin/assets/gutnm-dashboard.js/wp-content/plugins/gutenium/includes/admin/assets/widgets-cnt.js
Script Paths
/wp-content/plugins/gutenium/includes/admin/assets/ajax-save.js/wp-content/plugins/gutenium/includes/admin/assets/gutnm-dashboard.js/wp-content/plugins/gutenium/includes/admin/assets/widgets-cnt.js
Version Parameters
gutenium?ver=gutenium-blocks?ver=

HTML / DOM Fingerprints

CSS Classes
gutnm-blocks
HTML Comments
<!-- GUTNM Blocks --><!-- GUTNM Admin Notice -->
Data Attributes
data-gutenium-block-iddata-gutenium-optionsdata-gutenium-saved-settings
JS Globals
gutnm_ajax_object
FAQ

Frequently Asked Questions about Gutenium Blocks