Block AdBlock Security & Risk Analysis

wordpress.org/plugins/kill-adblock

Block AdBlock detects site visitors who have enabled adblocking software, and allows publishers to engage these users via customized display messages.

100 active installs v1.4 PHP + WP 3.2+ Updated Jul 2, 2018
adblockadblock-blockeranti-adblockerblock-ad-blockblock-adblock
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Block AdBlock Safe to Use in 2026?

Generally Safe

Score 85/100

Block AdBlock has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The 'kill-adblock' v1.4 plugin exhibits a seemingly strong security posture based on the provided static analysis and vulnerability history. The absence of identified CVEs and the clean taint analysis results are positive indicators. The plugin also appears to avoid common risky practices like raw SQL queries and extensive file operations. However, a significant concern arises from the low percentage of properly escaped output (35%). This suggests a potential for cross-site scripting (XSS) vulnerabilities, where user-supplied data could be rendered unescaped, leading to arbitrary code execution in the user's browser. While the attack surface is reported as zero, the output escaping issue presents a latent risk that needs careful consideration. The plugin's strengths lie in its lack of known vulnerabilities and avoidance of direct database manipulation risks. The primary weakness lies in the inadequate output sanitization, which, despite the lack of current CVEs, could be exploited if an attacker finds a way to inject malicious content into data displayed by the plugin.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Block AdBlock Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Block AdBlock Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
31
17 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

35% escaped48 total outputs
Attack Surface

Block AdBlock Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_initadmin-option.php:18
actionadmin_menuadmin-option.php:20
actionplugins_loadedinit.php:21
actionwp_headinit.php:381
actionwp_footerinit.php:403
actionwp_print_scriptsinit.php:418
Maintenance & Trust

Block AdBlock Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJul 2, 2018
PHP min version
Downloads26K

Community Trust

Rating70/100
Number of ratings26
Active installs100
Developer Profile

Block AdBlock Developer Profile

Admiral

3 plugins · 440 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Block AdBlock

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kill-adblock/css/style.css/wp-content/plugins/kill-adblock/js/kill-adblock.js
Script Paths
/wp-content/plugins/kill-adblock/js/kill-adblock.js
Version Parameters
kill-adblock/css/style.css?ver=kill-adblock/js/kill-adblock.js?ver=

HTML / DOM Fingerprints

CSS Classes
kill-adblockclose-btnkill-adblock-hidekill-adblock-1kill-adblock-2kill-adblock-bodykill-adblock-3
Data Attributes
baitClassbaitStyle
JS Globals
KillAdBlock
FAQ

Frequently Asked Questions about Block AdBlock