Heroic Glossary – Block for building Glossaries, Dictionaries and more Security & Risk Analysis

wordpress.org/plugins/heroic-glossary

The best WordPress glossary builder plugin to create and manage your own glossary of terms.

4K active installs v2.0.1 PHP 7.4+ WP 6.0+ Updated Jan 5, 2026
blockdefinitiondictionaryglossaryterms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Heroic Glossary – Block for building Glossaries, Dictionaries and more Safe to Use in 2026?

Generally Safe

Score 100/100

Heroic Glossary – Block for building Glossaries, Dictionaries and more has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The heroic-glossary v2.0.1 plugin exhibits an exceptionally strong security posture based on the provided static analysis. The absence of any identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events, combined with a complete lack of unprotected entry points, significantly minimizes its attack surface. Furthermore, the code analysis reveals no dangerous functions, no direct SQL queries (all are prepared), and all output is properly escaped, indicating robust secure coding practices. The plugin also avoids file operations, external HTTP requests, and relies on WordPress's built-in security mechanisms like nonces and capability checks, though the lack of these specific checks being *detected* might be due to the absence of relevant code paths rather than an oversight.

The vulnerability history is equally impressive, with zero recorded CVEs of any severity. This, along with the absence of taint analysis findings, strongly suggests a well-maintained and secure codebase that has not historically posed a risk to WordPress sites. The plugin's strengths lie in its minimal attack surface, adherence to secure coding principles for SQL and output handling, and a clean security history. The only potential area for deeper scrutiny, if more detailed code inspection were available, would be to confirm the expected implementation of nonces and capability checks for any underlying functionalities that might not be immediately apparent in a high-level static analysis.

In conclusion, the heroic-glossary v2.0.1 plugin appears to be a highly secure option. The data indicates excellent development practices with a negligible attack surface and no historical vulnerabilities. While a perfect security score is rare, this plugin comes very close based on the provided metrics, making it a low-risk choice for WordPress users.

Vulnerabilities
None known

Heroic Glossary – Block for building Glossaries, Dictionaries and more Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Heroic Glossary – Block for building Glossaries, Dictionaries and more Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Heroic Glossary – Block for building Glossaries, Dictionaries and more Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Heroic Glossary – Block for building Glossaries, Dictionaries and more Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.0
Last updatedJan 5, 2026
PHP min version7.4
Downloads50K

Community Trust

Rating76/100
Number of ratings10
Active installs4K
Developer Profile

Heroic Glossary – Block for building Glossaries, Dictionaries and more Developer Profile

HeroThemes

3 plugins · 16K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Heroic Glossary – Block for building Glossaries, Dictionaries and more

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/heroic-glossary/dist/blocks.style.build.css/wp-content/plugins/heroic-glossary/dist/blocks.editor.build.css
Script Paths
/wp-content/plugins/heroic-glossary/dist/blocks.build.js
Version Parameters
heroic-glossary/dist/blocks.style.build.css?ver=heroic-glossary/dist/blocks.editor.build.css?ver=heroic-glossary/dist/blocks.build.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-block-ht-glossary-heroic-glossary
Data Attributes
data-type="ht-glossary/heroic-glossary"data-align="center"
FAQ

Frequently Asked Questions about Heroic Glossary – Block for building Glossaries, Dictionaries and more