Info Blocks Security & Risk Analysis

wordpress.org/plugins/info-blocks

A gutenberg block for creating alerts, information or update text

10 active installs v1.0.0 PHP 5.6+ WP 5.0+ Updated Dec 12, 2018
alertblocksgutenberginformation
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Info Blocks Safe to Use in 2026?

Generally Safe

Score 85/100

Info Blocks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "info-blocks" plugin version 1.0.0 exhibits a strong security posture based on the static analysis. The absence of any identified dangerous functions, raw SQL queries, unescaped output, file operations, or external HTTP requests is a significant positive. Furthermore, the fact that all SQL queries are prepared and all output is properly escaped demonstrates a commitment to fundamental security best practices within the analyzed code. The zero-count for vulnerabilities in its history further reinforces this positive assessment, suggesting a history of secure development or rapid patching of any past issues.

However, a notable concern arises from the complete lack of any identified entry points (AJAX handlers, REST API routes, shortcodes, cron events). While this drastically reduces the attack surface, it also implies that the plugin may not have any functional output or interaction points that could be subjected to security scrutiny. If the plugin is intended to perform any actions or display any information, the absence of these standard interaction mechanisms in the analysis could indicate either a very minimal plugin or potential blind spots in the static analysis itself. The complete absence of nonce and capability checks across all identified (albeit zero) entry points is a direct consequence of this lack of interaction points and does not represent a specific vulnerability in this version, but it is a standard security practice that would be expected in any functional plugin.

In conclusion, "info-blocks" v1.0.0 appears to be a very secure plugin based on the provided static analysis data, demonstrating excellent coding hygiene and a clean vulnerability history. The primary "weakness" is the apparent lack of any functional entry points, which could either mean the plugin is extremely basic or that the analysis might have missed typical interaction vectors. Without functional entry points, the risk of traditional web vulnerabilities is minimal to non-existent.

Vulnerabilities
None known

Info Blocks Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Info Blocks Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Info Blocks Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionenqueue_block_assetssrc\init.php:33
actionenqueue_block_editor_assetssrc\init.php:64
Maintenance & Trust

Info Blocks Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedDec 12, 2018
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Info Blocks Developer Profile

Igor Benic

12 plugins · 2K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
479 days
View full developer profile
Detection Fingerprints

How We Detect Info Blocks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/info-blocks/dist/blocks.style.build.css/wp-content/plugins/info-blocks/dist/blocks.build.js/wp-content/plugins/info-blocks/dist/blocks.editor.build.css
Script Paths
/wp-content/plugins/info-blocks/dist/blocks.build.js

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Info Blocks