
IndieBlocks Security & Risk Analysis
wordpress.org/plugins/indieblocksUse blocks, and, optionally, "short-form" post types to easily "IndieWebify" your WordPress site.
Is IndieBlocks Safe to Use in 2026?
Generally Safe
Score 97/100IndieBlocks has a strong security track record. Known vulnerabilities have been patched promptly.
The indieblocks plugin v0.13.3 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by largely utilizing prepared statements for SQL queries and properly escaping a high percentage of its output. The absence of dangerous functions, file operations, and critical taint flows is also encouraging. However, several concerns warrant attention. The presence of an unprotected REST API route represents a significant attack vector. While the total attack surface isn't exceptionally large, the unprotected entry point is a critical flaw that could be exploited. The plugin's history of two CVEs, including a high and a medium severity vulnerability, with one being a Cross-site Scripting (XSS) and the other Server-Side Request Forgery (SSRF), is a red flag. Although there are currently no unpatched vulnerabilities, this history suggests a recurring pattern of security weaknesses that require careful monitoring and prompt patching of future issues. The last vulnerability being in the near future (2025-06-12) may be a data anomaly but doesn't negate the past issues. Overall, while the code quality shows some positive aspects, the unprotected entry point and the past vulnerability history necessitate vigilance.
Key Concerns
- REST API route without permission callbacks
- History of High severity vulnerability
- History of Medium severity vulnerability
IndieBlocks Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
IndieBlocks <= 0.13.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via kind Parameter
IndieBlocks <= 0.13.1 - Unauthenticated Server-Side Request Forgery
IndieBlocks Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
IndieBlocks Attack Surface
AJAX Handlers 2
REST API Routes 2
WordPress Hooks 101
Scheduled Events 4
Maintenance & Trust
IndieBlocks Maintenance & Trust
Maintenance Signals
Community Trust
IndieBlocks Alternatives
Webmention
webmention
Enable conversation across the web.
IndieWeb
indieweb
IndieWeb for WordPress!
Simple Note
simple-note
The plugin allows you to create colored text notes in the new block editor.
Post Kinds
indieweb-post-kinds
Ever want to reply to someone else's post with a post on your own site? Or to "like" someone else's post, but with your own site?
IndieWeb Press This
indieweb-press-this
IndieWebified Press This bookmarklets.
IndieBlocks Developer Profile
4 plugins · 1K total installs
How We Detect IndieBlocks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/indieblocks/assets/location.css/wp-content/plugins/indieblocks/assets/location.js/wp-content/plugins/indieblocks/assets/location.jsindieblocks-locationindieblocksHTML / DOM Fingerprints
<!-- IndieBlocks Location Meta Box -->data-geo_addressdata-geo_latitudedata-geo_longitudeindieblocks_location_obj/wp-json/indieblocks/v1/location