Nova Blocks by Pixelgrade Security & Risk Analysis

wordpress.org/plugins/nova-blocks

A collection of distinctive Gutenberg blocks, committed to making your site shine like a newborn star.

900 active installs v2.1.14 PHP 7.4+ WP 5.9+ Updated Mar 5, 2026
blocksfull-site-editinggutenberggutenberg-blockspage-builder
96
A · Safe
CVEs total3
Unpatched0
Last CVEJan 26, 2026
Safety Verdict

Is Nova Blocks by Pixelgrade Safe to Use in 2026?

Generally Safe

Score 96/100

Nova Blocks by Pixelgrade has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Jan 26, 2026Updated 28d ago
Risk Assessment

The static analysis of nova-blocks v2.1.14 reveals a mixed security posture. While the plugin demonstrates good practices in areas like SQL query preparation, the lack of entry points like AJAX handlers, REST API routes, and shortcodes is a positive sign for reducing the immediate attack surface. However, concerns arise from the 76% output escaping rate, leaving a significant portion of outputs potentially vulnerable to Cross-Site Scripting (XSS). The presence of a file operation, though not immediately flagged as problematic, warrants closer inspection to understand its context and potential for abuse.

The plugin's vulnerability history is a significant red flag, with three known medium-severity CVEs, all of which are now patched according to the data. The common vulnerability type being Cross-Site Scripting (XSS) aligns with the static analysis finding of imperfect output escaping. The fact that the last vulnerability was in 2026 (which is in the future, likely a data entry error and should be interpreted as a recent past date) suggests a pattern of past vulnerabilities, even if they are currently addressed. This history, combined with the output escaping issues, indicates a recurring need for diligent security auditing and patching within the plugin's development lifecycle.

In conclusion, while nova-blocks v2.1.14 has strengths in its limited attack surface and SQL hygiene, the imperfect output escaping and historical XSS vulnerabilities are substantial concerns. Users should be aware of the potential for XSS if any of the unescaped outputs can be triggered by malicious input. The plugin's developers need to ensure consistent and complete output sanitization to mitigate these risks effectively.

Key Concerns

  • Partial output escaping (76%)
  • Known past vulnerabilities (3 medium)
  • File operations present
Vulnerabilities
3

Nova Blocks by Pixelgrade Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2025
2025
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2026-24528medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Nova Blocks <= 2.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 26, 2026 Patched in 2.1.10 (16d)
CVE-2025-31819medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Nova Blocks by Pixelgrade <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 1, 2025 Patched in 2.1.9 (316d)
CVE-2024-8241medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Nova Blocks by Pixelgrade <= 2.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute

Sep 9, 2024 Patched in 2.1.8 (1d)
Code Analysis
Analyzed Mar 16, 2026

Nova Blocks by Pixelgrade Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
32
104 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

76% escaped136 total outputs
Attack Surface

Nova Blocks by Pixelgrade Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filterrender_blockpackages\core\src\blocks\core\separator\init.php:88
Maintenance & Trust

Nova Blocks by Pixelgrade Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedMar 5, 2026
PHP min version7.4
Downloads45K

Community Trust

Rating0/100
Number of ratings0
Active installs900
Developer Profile

Nova Blocks by Pixelgrade Developer Profile

pixelgrade

8 plugins · 37K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
214 days
View full developer profile
Detection Fingerprints

How We Detect Nova Blocks by Pixelgrade

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nova-blocks/assets/css/editor.css/wp-content/plugins/nova-blocks/assets/js/editor.js/wp-content/plugins/nova-blocks/assets/css/style.css/wp-content/plugins/nova-blocks/packages/block-library/build/author-box.js
Script Paths
/wp-content/plugins/nova-blocks/assets/js/editor.js/wp-content/plugins/nova-blocks/packages/block-library/build/author-box.js
Version Parameters
nova-blocks/assets/css/editor.css?ver=nova-blocks/assets/js/editor.js?ver=nova-blocks/assets/css/style.css?ver=nova-blocks/packages/block-library/build/author-box.js?ver=

HTML / DOM Fingerprints

CSS Classes
nb-author-boxnb-author-box__avatarnb-author-box__detailsnb-author-box__namenb-author-box__descriptionnb-author-box__footernb-author-box__linksnb-author-box__social-link+1 more
Data Attributes
itemscopeitemtype="https://schema.org/Person"
FAQ

Frequently Asked Questions about Nova Blocks by Pixelgrade