Magical Blocks – Elementor Style Blocks for Gutenberg Security & Risk Analysis

wordpress.org/plugins/magical-blocks

Get Elementor vibe in the WordPress Editor! Powerful Gutenberg blocks with Flexbox containers, responsive controls, and professional design options.

1K active installs v2.0.0 PHP 7.4+ WP 6.0+ Updated Dec 11, 2025
blockscontainerelementor-alternativegutenbergpage-builder
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 1, 2025
Safety Verdict

Is Magical Blocks – Elementor Style Blocks for Gutenberg Safe to Use in 2026?

Generally Safe

Score 99/100

Magical Blocks – Elementor Style Blocks for Gutenberg has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 1, 2025Updated 3mo ago
Risk Assessment

The "magical-blocks" plugin v2.0.0 exhibits a very strong security posture based on the provided static analysis. The complete absence of any identified dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, or unsanitized taint flows is highly commendable. The attack surface appears to be meticulously secured, with no unprotected entry points detected. This indicates a development team that prioritizes secure coding practices and thorough input validation/output escaping.

However, the plugin's vulnerability history presents a significant concern. The presence of a past medium-severity Cross-Site Scripting (XSS) vulnerability, even though it is reported as patched, suggests that the plugin has previously been susceptible to common web attack vectors. The fact that a vulnerability existed at all, despite the current static analysis findings, warrants continued vigilance. It's possible that the current version has effectively mitigated previous issues, but it highlights a potential area where vulnerabilities can emerge if not actively maintained.

In conclusion, "magical-blocks" v2.0.0 demonstrates excellent internal coding security with no immediate risks identified in the static analysis. The strengths lie in its clean code, prepared SQL statements, and proper output escaping. The primary weakness is the historical medium-severity XSS vulnerability, which suggests a need for ongoing security audits and rapid patching of any future discoveries to maintain this otherwise impressive security profile.

Key Concerns

  • Medium severity CVE in history
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
1

Magical Blocks – Elementor Style Blocks for Gutenberg Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-31844medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Magical Blocks <= 1.0.12 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 1, 2025 Patched in 2.0.0 (332d)
Code Analysis
Analyzed Mar 16, 2026

Magical Blocks – Elementor Style Blocks for Gutenberg Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
312 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped312 total outputs
Attack Surface

Magical Blocks – Elementor Style Blocks for Gutenberg Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionenqueue_block_editor_assetsincludes\class-magical-blocks-assets.php:26
actionenqueue_block_assetsincludes\class-magical-blocks-assets.php:27
actionwp_enqueue_scriptsincludes\class-magical-blocks-assets.php:28
filterblock_categories_allincludes\class-magical-blocks-blocks.php:48
actioninitincludes\class-magical-blocks-blocks.php:54
actioninitincludes\class-magical-blocks.php:65
actioninitincludes\class-magical-blocks.php:70
actionadmin_initincludes\class-magical-blocks.php:74
actionplugins_loadedmagical-blocks.php:139
actionadmin_noticesmagical-blocks.php:203
actioninitpatterns\class-magical-blocks-patterns.php:42
actioninitpatterns\class-magical-blocks-patterns.php:43
Maintenance & Trust

Magical Blocks – Elementor Style Blocks for Gutenberg Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 11, 2025
PHP min version7.4
Downloads32K

Community Trust

Rating0/100
Number of ratings0
Active installs1K
Developer Profile

Magical Blocks – Elementor Style Blocks for Gutenberg Developer Profile

Noor Alam

102 plugins · 29K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
233 days
View full developer profile
Detection Fingerprints

How We Detect Magical Blocks – Elementor Style Blocks for Gutenberg

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/magical-blocks/assets/css/frontend.min.css/wp-content/plugins/magical-blocks/assets/css/editor.min.css/wp-content/plugins/magical-blocks/assets/js/frontend.js/wp-content/plugins/magical-blocks/assets/js/editor.js
Script Paths
/wp-content/plugins/magical-blocks/assets/js/frontend.js/wp-content/plugins/magical-blocks/assets/js/editor.js
Version Parameters
magical-blocks/assets/css/frontend.min.css?ver=magical-blocks/assets/css/editor.min.css?ver=magical-blocks/assets/js/frontend.js?ver=magical-blocks/assets/js/editor.js?ver=

HTML / DOM Fingerprints

CSS Classes
magical-blocks-containermagical-blocks-grid
Data Attributes
data-magical-blocks-responsive
JS Globals
window.magicalBlocksFrontendwindow.magicalBlocksEditor
FAQ

Frequently Asked Questions about Magical Blocks – Elementor Style Blocks for Gutenberg