nBlocks – Responsive Gutenberg News Blocks Security & Risk Analysis

wordpress.org/plugins/nblocks

Requires Gutenberg: true Gutenberg compatible: true Icon URI: icon.svg

10 active installs v1.0.2 PHP 7.0+ WP 5.8+ Updated Unknown
blocksgutenbergn-blockspostfilter-blockswordpress-blocks
77
B · Generally Safe
CVEs total1
Unpatched1
Last CVENov 18, 2024
Safety Verdict

Is nBlocks – Responsive Gutenberg News Blocks Safe to Use in 2026?

Mostly Safe

Score 77/100

nBlocks – Responsive Gutenberg News Blocks is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Nov 18, 2024
Risk Assessment

The static analysis of nblocks v1.0.2 reveals a generally strong security posture in terms of code practices. There are no detected dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. The plugin also avoids file operations and external HTTP requests, which further limits potential attack vectors. Crucially, the absence of any taint analysis findings or unescaped outputs from the code signals suggests that direct code execution or data leakage vulnerabilities are unlikely to be present within the analyzed code itself.

However, the plugin's security is significantly undermined by its vulnerability history. The presence of one high-severity CVE, specifically a 'PHP Remote File Inclusion' vulnerability, that is currently unpatched is a major concern. This type of vulnerability, especially if exploitable without authentication, could allow an attacker to execute arbitrary PHP code on the server, leading to complete site compromise. The fact that this vulnerability is recent (November 2024) and remains unpatched indicates a lack of timely security maintenance or a significant oversight by the developers.

While the plugin exhibits good secure coding practices in its current version, the existence of a critical, unpatched vulnerability overrides these strengths. The risk associated with this plugin is therefore elevated. Users should be strongly advised to avoid using this version and seek an updated, patched version if available. If no patch exists, discontinuing use of this plugin is highly recommended.

Key Concerns

  • Unpatched high severity CVE
Vulnerabilities
1

nBlocks – Responsive Gutenberg News Blocks Security Vulnerabilities

CVEs by Year

1 CVE in 2024 · unpatched
2024
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2024-52450high · 8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

nBlocks <= 1.0.2 - Authenticated (Contributor+) Local File Inclusion

Nov 18, 2024Unpatched
Code Analysis
Analyzed Mar 16, 2026

nBlocks – Responsive Gutenberg News Blocks Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
169 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped169 total outputs
Attack Surface

nBlocks – Responsive Gutenberg News Blocks Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitblocks\post-filter\index.php:127
filterwp_kses_allowed_htmln-blocks.php:85
Maintenance & Trust

nBlocks – Responsive Gutenberg News Blocks Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedUnknown
PHP min version7.0
Downloads831

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

nBlocks – Responsive Gutenberg News Blocks Developer Profile

officialprocoders

1 plugin · 10 total installs

78
trust score
Avg Security Score
77/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect nBlocks – Responsive Gutenberg News Blocks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nblocks/blocks/post-filter/index.js/wp-content/plugins/nblocks/blocks/post-filter/style.css
Script Paths
/wp-content/plugins/nblocks/blocks/post-filter/index.js
Version Parameters
nblocks/blocks/post-filter/index.js?ver=nblocks/blocks/post-filter/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
nblock_latest_3col_rowlatest-nbolcknpub-medium-titlenpub-3col-masonrynblock_latest_3col_colcheck-in-viewthree-col-imgsize-npub-medium+13 more
Data Attributes
data-blockdata-post-iddata-settings
JS Globals
nblocks_settings
Shortcode Output
<div class="row nblock_latest_3col_row mx-0 latest-nbolck npub-medium-title npub-3col-masonry"><div class="col-lg-4 col-md-4 col-sm-6 col-xs-12 nblock_latest_3col_col pe-lg-3 check-in-view"><div class="three-col-img"><span class="size-npub-medium">
FAQ

Frequently Asked Questions about nBlocks – Responsive Gutenberg News Blocks