Gutentools Security & Risk Analysis

wordpress.org/plugins/gutentools

Gutentools is a powerful block editor plugin designed for seamless full-site editing.

4K active installs v1.1.5 PHP 7.4+ WP 6.0+ Updated Mar 11, 2026
block-editorgutenberggutenberg-templates
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 21, 2026
Download
Safety Verdict

Is Gutentools Safe to Use in 2026?

Generally Safe

Score 99/100

Gutentools has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Apr 21, 2026Updated 2mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, Gutentools v1.1.5 exhibits a strong security posture with no identified critical vulnerabilities. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code demonstrates good practices by exclusively using prepared statements for SQL queries and having a high percentage of properly escaped output. The lack of dangerous functions, external HTTP requests, and recorded vulnerabilities in its history further contribute to its positive security assessment.

Key Concerns

  • Zero capability checks present
  • Zero nonce checks present
  • Low percentage of output escaping (83%)
Vulnerabilities
1 published

Gutentools Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-1395medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Gutentools <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Slider Block Attributes

Apr 21, 2026 Patched in 1.1.4 (1d)
Version History

Gutentools Release Timeline

v1.1.5Current
v1.1.4
v1.1.31 CVE
v1.1.21 CVE
v1.1.11 CVE
v1.1.01 CVE
v1.0.91 CVE
v1.0.81 CVE
v1.0.71 CVE
v1.0.61 CVE
v1.0.51 CVE
v1.0.41 CVE
v1.0.31 CVE
v1.0.21 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Gutentools Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
42
203 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped245 total outputs
Attack Surface

Gutentools Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actionenqueue_block_assetscore\block_configuration.php:25
filterblock_categories_allcore\block_configuration.php:26
actionafter_gutentools_gutentools_loadcore\block_configuration.php:27
actioninitcore\gutentools_block.php:42
actionwp_enqueue_scriptscore\gutentools_block.php:44
actionwp_enqueue_scriptscore\gutentools_block.php:45
actionwp_enqueue_scriptscore\gutentools_block.php:67
actionplugins_loadedgutentools.php:30
actioninitgutentools.php:93
actionadmin_noticesinc\admin-notice.php:19
actionadmin_menuinc\plugin-page.php:22
actionadmin_enqueue_scriptsinc\script_loader.php:18
actionwp_enqueue_scriptsinc\script_loader.php:19
actionenqueue_block_editor_assetsinc\script_loader.php:20
actionenqueue_block_assetsinc\script_loader.php:21
Maintenance & Trust

Gutentools Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version7.4
Downloads30K

Community Trust

Rating100/100
Number of ratings2
Active installs4K
Developer Profile

Gutentools Developer Profile

Gutentools

1 plugin · 4K total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Gutentools

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gutentools/assets/styles/editor.css

HTML / DOM Fingerprints

CSS Classes
gutentools-editor-style
JS Globals
Gutentools_VAR
FAQ

Frequently Asked Questions about Gutentools