Light Modal Block Security & Risk Analysis

wordpress.org/plugins/light-modal-block

Lightweight, customizable modal block for the WordPress block editor

2K active installs v1.9.0 PHP 7.0+ WP 6.6+ Updated Feb 22, 2026
blockgutenberglightboxmodalpopup
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Light Modal Block Safe to Use in 2026?

Generally Safe

Score 100/100

Light Modal Block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The static analysis of light-modal-block v1.9.0 reveals a very strong security posture. There are no identified entry points through AJAX handlers, REST API, shortcodes, or cron events that lack authentication or permission checks. The code demonstrates excellent security practices by using prepared statements for all SQL queries, ensuring proper output escaping, and avoiding dangerous functions and file operations. Furthermore, no external HTTP requests or bundled libraries that could introduce vulnerabilities were found. The absence of any recorded vulnerabilities, including critical or high severity ones, further reinforces this positive assessment.

While the current version appears exceptionally secure based on this static analysis, it's important to note the complete absence of nonce and capability checks across all potential entry points. While the static analysis indicates no direct entry points were found, this lack of checks could represent a theoretical weakness if new entry points were to be introduced in future versions or if the analysis missed certain indirect interactions. However, given the thoroughness suggested by the other positive findings, this is a minor concern. The plugin's history of zero vulnerabilities is a significant strength, indicating a commitment to security from its developers.

Key Concerns

  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

Light Modal Block Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Light Modal Block Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Light Modal Block Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actioninitlight-modal-block.php:25
filterrender_block_core/post-templatelight-modal-block.php:79
filterrender_block_core/buttonlight-modal-block.php:103
Maintenance & Trust

Light Modal Block Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 22, 2026
PHP min version7.0
Downloads14K

Community Trust

Rating100/100
Number of ratings12
Active installs2K
Developer Profile

Light Modal Block Developer Profile

David Jensen

5 plugins · 5K total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Light Modal Block

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/light-modal-block/build/index.js/wp-content/plugins/light-modal-block/build/style-index.css
Script Paths
/wp-content/plugins/light-modal-block/build/index.js
Version Parameters
light-modal-block/build/style-index.css?ver=light-modal-block/build/index.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-block-cloudcatch-light-modal-block
Data Attributes
data-trigger-modaldata-modal-id
FAQ

Frequently Asked Questions about Light Modal Block