Magic Content & CTA Box Builder – Advanced Gutenberg Blocks for Flexible Page Sections, Headers, Buttons, Shape Dividers, and Layout Options Security & Risk Analysis

wordpress.org/plugins/magic-content-box-lite

Advanced Gutenberg Blocks for Flexible Page Sections, Call to Action, Headers, Buttons, Shape Dividers, and Layout Options

6K active installs v1.1.3 PHP 5.3+ WP + Updated Dec 10, 2025
blockblocksbuttoncall-to-actiongutenberg-block
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Magic Content & CTA Box Builder – Advanced Gutenberg Blocks for Flexible Page Sections, Headers, Buttons, Shape Dividers, and Layout Options Safe to Use in 2026?

Generally Safe

Score 100/100

Magic Content & CTA Box Builder – Advanced Gutenberg Blocks for Flexible Page Sections, Headers, Buttons, Shape Dividers, and Layout Options has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The static analysis of "magic-content-box-lite" v1.1.3 indicates a strong security posture in several key areas. The absence of any detected dangerous functions, file operations, external HTTP requests, and the complete reliance on prepared statements for SQL queries demonstrate good development practices. Furthermore, all output is properly escaped, and the analysis reports no taint flows, suggesting a low risk of code injection or cross-site scripting vulnerabilities stemming from the code itself. The plugin also has no recorded vulnerability history, which is a positive indicator.

However, the data does reveal significant areas for concern. The plugin exhibits a complete lack of security checks at its entry points. With zero AJAX handlers, REST API routes, shortcodes, or cron events, there are no apparent mechanisms for authentication or authorization, or even nonce checks. This means that if any functionalities were to be added or discovered that could be triggered externally, they would be completely unprotected. While currently there is no attack surface with unauthenticated entry points, this fundamental absence of security controls is a major weakness. The vulnerability history being empty is a positive sign, but it does not negate the risks introduced by the lack of security checks within the code.

Key Concerns

  • No nonce checks on potential entry points
  • No capability checks on potential entry points
  • Zero AJAX handlers without auth checks (potential future risk)
  • Zero REST API routes without permission callbacks (potential future risk)
Vulnerabilities
None known

Magic Content & CTA Box Builder – Advanced Gutenberg Blocks for Flexible Page Sections, Headers, Buttons, Shape Dividers, and Layout Options Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Magic Content & CTA Box Builder – Advanced Gutenberg Blocks for Flexible Page Sections, Headers, Buttons, Shape Dividers, and Layout Options Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

Magic Content & CTA Box Builder – Advanced Gutenberg Blocks for Flexible Page Sections, Headers, Buttons, Shape Dividers, and Layout Options Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedmagic-content-box-lite.php:80
actionwp_headsrc\fonts.php:12
actioninitsrc\init.php:28
actionenqueue_block_editor_assetssrc\init.php:73
filterblock_categoriessrc\init.php:78
Maintenance & Trust

Magic Content & CTA Box Builder – Advanced Gutenberg Blocks for Flexible Page Sections, Headers, Buttons, Shape Dividers, and Layout Options Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 10, 2025
PHP min version5.3
Downloads222K

Community Trust

Rating0/100
Number of ratings0
Active installs6K
Developer Profile

Magic Content & CTA Box Builder – Advanced Gutenberg Blocks for Flexible Page Sections, Headers, Buttons, Shape Dividers, and Layout Options Developer Profile

AF themes

64 plugins · 96K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
160 days
View full developer profile
Detection Fingerprints

How We Detect Magic Content & CTA Box Builder – Advanced Gutenberg Blocks for Flexible Page Sections, Headers, Buttons, Shape Dividers, and Layout Options

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/magic-content-box-lite/dist/blocks.style.build.css/wp-content/plugins/magic-content-box-lite/src/assets/fontawesome/css/all.css
Script Paths
/wp-content/plugins/magic-content-box-lite/dist/blocks.build.js
Version Parameters
magic-content-box-lite/dist/blocks.style.build.css?ver=magic-content-box-lite/src/assets/fontawesome/css/all.css?ver=magic-content-box-lite/dist/blocks.build.js?ver=magic-content-box-lite/dist/blocks.editor.build.css?ver=

HTML / DOM Fingerprints

CSS Classes
magic-content-box-lite-wrapper
Data Attributes
data-blockdata-block-type
JS Globals
magic_content_box_lite_editor_scriptmagic_content_box_lite_frontend_script
FAQ

Frequently Asked Questions about Magic Content & CTA Box Builder – Advanced Gutenberg Blocks for Flexible Page Sections, Headers, Buttons, Shape Dividers, and Layout Options