Massive Addons for Gutenberg and WordPress Security & Risk Analysis

wordpress.org/plugins/massive-addons-for-wp-blocks

Massive Addons for gutenberg extension, Beautifully designed unique elements, Includes Premium quality addons For Gutenberg Page Builder.

10 active installs v1.3 PHP + WP 4.8+ Updated Mar 20, 2021
addons-for-gutenbergall-in-one-pluginblocks-for-gutenberggutenberg-page-buildermassive-addons-for-gutenberg
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Massive Addons for Gutenberg and WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

Massive Addons for Gutenberg and WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of "massive-addons-for-wp-blocks" v1.3 indicates a plugin with a very limited attack surface from an entry point perspective. There are no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed, which is a positive sign for reducing direct attack vectors. Furthermore, the plugin utilizes prepared statements for all SQL queries, which is a critical security practice and effectively mitigates SQL injection risks. The absence of dangerous functions, file operations, and external HTTP requests is also encouraging. However, a significant concern arises from the complete lack of output escaping (0% properly escaped). This means that any data displayed to users, if originating from a potentially untrusted source or containing user-generated content, could be vulnerable to Cross-Site Scripting (XSS) attacks. The absence of nonce checks and capability checks also suggests a lack of proper authorization and protection against Cross-Site Request Forgery (CSRF) for any operations that might exist but are not detected as entry points by the static analysis. The plugin's vulnerability history is remarkably clean, with no known CVEs. This, combined with the secure SQL practices, suggests a development team that, at least in terms of SQL and known vulnerabilities, prioritizes security. However, the severe lack of output escaping represents a significant blind spot that could easily lead to vulnerabilities if not addressed. While the plugin has a strong foundation in SQL security and a clean history, the complete omission of output escaping creates a substantial risk that overshadows these strengths.

Key Concerns

  • No output escaping detected
  • No nonce checks detected
  • No capability checks detected
Vulnerabilities
None known

Massive Addons for Gutenberg and WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Massive Addons for Gutenberg and WordPress Release Timeline

v1.3Current
v1.2.1
v1.2
v1.1
v1.0
Code Analysis
Analyzed Apr 16, 2026

Massive Addons for Gutenberg and WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
590
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped590 total outputs
Attack Surface

Massive Addons for Gutenberg and WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitmain.php:10
actionenqueue_block_editor_assetsmain.php:11
filterblock_categoriesmain.php:12
actionenqueue_block_assetsmain.php:13
Maintenance & Trust

Massive Addons for Gutenberg and WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMar 20, 2021
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Massive Addons for Gutenberg and WordPress Developer Profile

nasir179125

4 plugins · 32K total installs

61
trust score
Avg Security Score
74/100
Avg Patch Time
281 days
View full developer profile
Detection Fingerprints

How We Detect Massive Addons for Gutenberg and WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/massive-addons-for-wp-blocks/assets/css/bootstrap.css/wp-content/plugins/massive-addons-for-wp-blocks/assets/css/massive_custom_styles.min.css/wp-content/plugins/massive-addons-for-wp-blocks/blocks/accordions.js/wp-content/plugins/massive-addons-for-wp-blocks/blocks/advanced-heading.js/wp-content/plugins/massive-addons-for-wp-blocks/blocks/call-to-action.js/wp-content/plugins/massive-addons-for-wp-blocks/blocks/carousel.js/wp-content/plugins/massive-addons-for-wp-blocks/blocks/charts.js/wp-content/plugins/massive-addons-for-wp-blocks/blocks/clients.js+38 more
Script Paths
/wp-content/plugins/massive-addons-for-wp-blocks/blocks/accordions.js/wp-content/plugins/massive-addons-for-wp-blocks/blocks/advanced-heading.js/wp-content/plugins/massive-addons-for-wp-blocks/blocks/call-to-action.js/wp-content/plugins/massive-addons-for-wp-blocks/blocks/carousel.js/wp-content/plugins/massive-addons-for-wp-blocks/blocks/charts.js/wp-content/plugins/massive-addons-for-wp-blocks/blocks/clients.js+38 more
Version Parameters
/wp-content/plugins/massive-addons-for-wp-blocks/assets/css/massive_custom_styles.min.css?ver=/wp-content/plugins/massive-addons-for-wp-blocks/assets/js/icon.js?ver=

HTML / DOM Fingerprints

CSS Classes
mba-blocks-cssnbg-bootstrapnbg-front-accordionsnbg-front-advanced-headingnbg-front-call-to-actionnbg-front-carouselnbg-front-chartsnbg-front-clients+80 more
HTML Comments
Design made by Webcodingplace from https://wordpress.org/plugins/mega-blocks-for-gutenberg/
Data Attributes
data-nbg-headingdata-nbg-aligndata-nbg-lineheightdata-nbg-sizedata-nbg-margindata-nbg-color+482 more
JS Globals
nbg_vars
FAQ

Frequently Asked Questions about Massive Addons for Gutenberg and WordPress