
Nova Blocks by Pixelgrade Security & Risk Analysis
wordpress.org/plugins/nova-blocksA collection of distinctive Gutenberg blocks, committed to making your site shine like a newborn star.
Is Nova Blocks by Pixelgrade Safe to Use in 2026?
Generally Safe
Score 96/100Nova Blocks by Pixelgrade has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of nova-blocks v2.1.14 reveals a mixed security posture. While the plugin demonstrates good practices in areas like SQL query preparation, the lack of entry points like AJAX handlers, REST API routes, and shortcodes is a positive sign for reducing the immediate attack surface. However, concerns arise from the 76% output escaping rate, leaving a significant portion of outputs potentially vulnerable to Cross-Site Scripting (XSS). The presence of a file operation, though not immediately flagged as problematic, warrants closer inspection to understand its context and potential for abuse.
The plugin's vulnerability history is a significant red flag, with three known medium-severity CVEs, all of which are now patched according to the data. The common vulnerability type being Cross-Site Scripting (XSS) aligns with the static analysis finding of imperfect output escaping. The fact that the last vulnerability was in 2026 (which is in the future, likely a data entry error and should be interpreted as a recent past date) suggests a pattern of past vulnerabilities, even if they are currently addressed. This history, combined with the output escaping issues, indicates a recurring need for diligent security auditing and patching within the plugin's development lifecycle.
In conclusion, while nova-blocks v2.1.14 has strengths in its limited attack surface and SQL hygiene, the imperfect output escaping and historical XSS vulnerabilities are substantial concerns. Users should be aware of the potential for XSS if any of the unescaped outputs can be triggered by malicious input. The plugin's developers need to ensure consistent and complete output sanitization to mitigate these risks effectively.
Key Concerns
- Partial output escaping (76%)
- Known past vulnerabilities (3 medium)
- File operations present
Nova Blocks by Pixelgrade Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Nova Blocks <= 2.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Nova Blocks by Pixelgrade <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
Nova Blocks by Pixelgrade <= 2.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute
Nova Blocks by Pixelgrade Code Analysis
Output Escaping
Nova Blocks by Pixelgrade Attack Surface
WordPress Hooks 1
Maintenance & Trust
Nova Blocks by Pixelgrade Maintenance & Trust
Maintenance Signals
Community Trust
Nova Blocks by Pixelgrade Alternatives
Greenshift – animation and page builder blocks
greenshift-animation-and-page-builder-blocks
More than 20 special blocks for Gutenberg to build complex pages and animations with highest possible web vitals score.
Gutenwave Blocks – Gutenberg Page Builder Blocks for Block Editor & FSE
gutenwave-blocks
Build stunning websites with Gutenberg. Free responsive blocks, starter templates & full site editing support in one lightweight plugin.
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Page Builder Gutenberg Blocks – CoBlocks
coblocks
CoBlocks is a suite of page builder WordPress blocks for Gutenberg, with 10+ new blocks and a true page builder experience with rows and columns.
Nova Blocks by Pixelgrade Developer Profile
8 plugins · 37K total installs
How We Detect Nova Blocks by Pixelgrade
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nova-blocks/assets/css/editor.css/wp-content/plugins/nova-blocks/assets/js/editor.js/wp-content/plugins/nova-blocks/assets/css/style.css/wp-content/plugins/nova-blocks/packages/block-library/build/author-box.js/wp-content/plugins/nova-blocks/assets/js/editor.js/wp-content/plugins/nova-blocks/packages/block-library/build/author-box.jsnova-blocks/assets/css/editor.css?ver=nova-blocks/assets/js/editor.js?ver=nova-blocks/assets/css/style.css?ver=nova-blocks/packages/block-library/build/author-box.js?ver=HTML / DOM Fingerprints
nb-author-boxnb-author-box__avatarnb-author-box__detailsnb-author-box__namenb-author-box__descriptionnb-author-box__footernb-author-box__linksnb-author-box__social-link+1 moreitemscopeitemtype="https://schema.org/Person"