OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System Security & Risk Analysis

wordpress.org/plugins/offcanvas-block

Build responsive off-canvas menus, drawers, and popups in WordPress using a lightweight Gutenberg block with advanced triggers and animations.

800 active installs v2.0.4 PHP 7.1+ WP 6.5+ Updated Apr 15, 2026
blockdraweroffcanvaspopupslide-menu
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System Safe to Use in 2026?

Generally Safe

Score 100/100

OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The offcanvas-block plugin v2.0.3 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection risks, file operations, and external HTTP requests, coupled with 100% proper output escaping and the use of prepared statements for all SQL queries, are significant strengths. The plugin also demonstrates good practice by incorporating capability checks. However, a notable concern is the complete lack of nonce checks, which could be a point of exploitation for certain types of attacks, especially if any of the entry points were to become exposed or if capabilities were not strictly enforced in a more complex real-world scenario.

The vulnerability history is a clean slate, with no recorded CVEs, indicating a likely history of secure development and maintenance. This, combined with the strong code signals, suggests a generally low risk profile for this plugin. The limited attack surface, consisting solely of a single shortcode with no explicit mention of authentication checks on this specific entry point, is also a positive factor. Overall, while the plugin adheres to many security best practices, the absence of nonce checks is a point that warrants consideration in a comprehensive security assessment.

Key Concerns

  • Missing nonce checks
Vulnerabilities
None known

OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System Release Timeline

v2.0.4Current
v2.0.3
v2.0.2
v2.0.1
v2.0.0
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius

Output Escaping

100% escaped5 total outputs
Attack Surface

OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[offcanvas-block] includes\class-obPlugin.php:10
WordPress Hooks 10
actioninitincludes\class-obAdmin.php:14
actionadmin_enqueue_scriptsincludes\class-obAdmin.php:15
actionadmin_menuincludes\class-obAdmin.php:16
filtermanage_offcanvas-block_posts_columnsincludes\class-obAdmin.php:17
actionmanage_offcanvas-block_posts_custom_columnincludes\class-obAdmin.php:18
actionplugins_loadedincludes\class-obPlugin.php:8
actionadmin_enqueue_scriptsincludes\class-obPlugin.php:9
actioninitoffcanvas-block.php:7
actionenqueue_block_editor_assetsoffcanvas-block.php:8
actionwp_enqueue_scriptsoffcanvas-block.php:9
Maintenance & Trust

OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedApr 15, 2026
PHP min version7.1
Downloads11K

Community Trust

Rating100/100
Number of ratings1
Active installs800
Developer Profile

OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System Developer Profile

colorlibplugins

121 plugins · 740K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
130 days
View full developer profile
Detection Fingerprints

How We Detect OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/offcanvas-block/build/admin-post.js/wp-content/plugins/offcanvas-block/build/admin-post.css/wp-content/plugins/offcanvas-block/build/admin-dashboard.js/wp-content/plugins/offcanvas-block/build/admin-dashboard.css
Script Paths
/wp-content/plugins/offcanvas-block/offcanvas-block.php
Version Parameters
offcanvas-block/style.css?ver=offcanvas-block/build/admin-post.js?ver=offcanvas-block/build/admin-post.css?ver=offcanvas-block/build/admin-dashboard.js?ver=offcanvas-block/build/admin-dashboard.css?ver=

HTML / DOM Fingerprints

JS Globals
obIsPipeChecker
Shortcode Output
[offcanvas-block id=
FAQ

Frequently Asked Questions about OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System