Kenta Blocks – Responsive Blocks and block templates library Security & Risk Analysis

wordpress.org/plugins/kenta-blocks

Kenta Blocks is a set of responsive blocks with powerful options and pre-designed templates library.

3K active installs v1.4.5 PHP 7.4+ WP 5.6+ Updated Apr 22, 2025
block-editorgutenberg-blockspage-builder
98
A · Safe
CVEs total2
Unpatched0
Last CVEJun 6, 2024
Safety Verdict

Is Kenta Blocks – Responsive Blocks and block templates library Safe to Use in 2026?

Generally Safe

Score 98/100

Kenta Blocks – Responsive Blocks and block templates library has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Jun 6, 2024Updated 11mo ago
Risk Assessment

The Kenta Blocks plugin v1.4.5 presents a mixed security profile. On one hand, the static analysis reveals strong adherence to several secure coding practices, including 100% prepared SQL statements and properly escaped output. The absence of direct file operations and external HTTP requests in the analyzed code is also positive. However, the static analysis also highlights a significant concern: zero nonce checks and zero capability checks on its entry points, despite the presence of four capability checks in total, suggesting potential areas where authorization might be overlooked or improperly implemented. Furthermore, the lack of any taint analysis results could indicate limited testing or an inability of the analysis tools to effectively trace data flows within this version.

The vulnerability history is a major area of concern. With two known CVEs, including a high and a medium severity vulnerability, the plugin has a history of critical security flaws. The common vulnerability types like Cross-site Scripting and Missing Authorization directly align with potential weaknesses identified in the static analysis. While there are currently no unpatched vulnerabilities, the recurring nature of these serious issues suggests a pattern of vulnerabilities being introduced and subsequently fixed. The most recent vulnerability being in June 2024 further underscores the ongoing security challenges.

In conclusion, while Kenta Blocks v1.4.5 demonstrates good practices in areas like SQL querying and output escaping, its security posture is significantly undermined by its vulnerability history and the apparent lack of robust authorization checks on its entry points. The past occurrences of critical vulnerabilities like XSS and Missing Authorization, coupled with the absence of nonce checks, demand cautious use and ongoing vigilance. Users should prioritize keeping the plugin updated and be aware of its historical security weaknesses.

Key Concerns

  • Unpatched CVEs (0 currently)
  • High severity CVEs (1)
  • Medium severity CVEs (1)
  • Missing nonce checks on entry points
  • Bundled outdated library (Freemius v1.0)
Vulnerabilities
2

Kenta Blocks – Responsive Blocks and block templates library Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2024-35731medium · 5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Kenta Blocks – Responsive Blocks and block templates library <= 1.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jun 6, 2024 Patched in 1.4.0 (8d)

Kenta Gutenberg Blocks <= 1.0.7 - Missing Authorization

Nov 25, 2022 Patched in 1.1.0 (424d)
Code Analysis
Analyzed Mar 16, 2026

Kenta Blocks – Responsive Blocks and block templates library Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
91 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
2
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped91 total outputs
Attack Surface

Kenta Blocks – Responsive Blocks and block templates library Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actioninitcore\Assets.php:24
actionwp_enqueue_scriptscore\Assets.php:25
actionadmin_enqueue_scriptscore\Assets.php:26
actionsave_postcore\Assets.php:27
actionsave_post_wp_blockcore\Assets.php:28
actioninitcore\Bootstrap.php:37
filterwp_kses_allowed_htmlcore\Bootstrap.php:66
actioninitcore\Bootstrap.php:76
actionadmin_menucore\Bootstrap.php:78
actionrest_api_initcore\Bootstrap.php:79
actioncurrent_screencore\Bootstrap.php:81
filterexcerpt_moreinc\blocks\post-excerpt.php:68
filterexcerpt_lengthinc\blocks\post-excerpt.php:69
filterwoocommerce_product_get_rating_htmlinc\blocks\wc-product-rating.php:111
filterkb/posts_query_argsinc\hooks\wc-products-query.php:84
actionplugins_loadedkenta-blocks.php:95
Maintenance & Trust

Kenta Blocks – Responsive Blocks and block templates library Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 22, 2025
PHP min version7.4
Downloads68K

Community Trust

Rating0/100
Number of ratings0
Active installs3K
Developer Profile

Kenta Blocks – Responsive Blocks and block templates library Developer Profile

WP Moose

25 plugins · 14K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
147 days
View full developer profile
Detection Fingerprints

How We Detect Kenta Blocks – Responsive Blocks and block templates library

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kenta-blocks/dist/blocks.style.min.css/wp-content/plugins/kenta-blocks/dist/blocks.style.css/wp-content/plugins/kenta-blocks/dist/blocks.editor.min.css/wp-content/plugins/kenta-blocks/dist/blocks.editor.css/wp-content/plugins/kenta-blocks/dist/blocks.min.js/wp-content/plugins/kenta-blocks/dist/blocks.js/wp-content/plugins/kenta-blocks/dist/frontend.min.js/wp-content/plugins/kenta-blocks/dist/frontend.js+6 more
Script Paths
/wp-content/plugins/kenta-blocks/dist/blocks.min.js/wp-content/plugins/kenta-blocks/dist/blocks.js/wp-content/plugins/kenta-blocks/dist/frontend.min.js/wp-content/plugins/kenta-blocks/dist/frontend.js/wp-content/plugins/kenta-blocks/dist/wc-blocks.min.js/wp-content/plugins/kenta-blocks/dist/wc-blocks.js+2 more
Version Parameters
kenta-blocks/dist/blocks.style.min.css?ver=kenta-blocks/dist/blocks.editor.min.css?ver=kenta-blocks/dist/blocks.min.js?ver=kenta-blocks/dist/frontend.min.js?ver=kenta-blocks/dist/wc-blocks.min.js?ver=kenta-blocks/assets/fontawesome/css/all.min.css?ver=kenta-blocks/assets/vendor/slick/slick.min.js?ver=kenta-blocks/assets/vendor/slick/slick.css?ver=kenta-blocks/assets/vendor/particles/tsparticles.bundle.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
kenta-blockkenta-container
Data Attributes
data-kb-blockdata-kb-block-type
JS Globals
kenta_blocks_configKentaBlocks
REST Endpoints
/wp-json/kenta-blocks/v1/blocks
FAQ

Frequently Asked Questions about Kenta Blocks – Responsive Blocks and block templates library