
OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System Security & Risk Analysis
wordpress.org/plugins/offcanvas-blockBuild responsive off-canvas menus, drawers, and popups in WordPress using a lightweight Gutenberg block with advanced triggers and animations.
Is OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System Safe to Use in 2026?
Generally Safe
Score 100/100OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The offcanvas-block plugin v2.0.3 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection risks, file operations, and external HTTP requests, coupled with 100% proper output escaping and the use of prepared statements for all SQL queries, are significant strengths. The plugin also demonstrates good practice by incorporating capability checks. However, a notable concern is the complete lack of nonce checks, which could be a point of exploitation for certain types of attacks, especially if any of the entry points were to become exposed or if capabilities were not strictly enforced in a more complex real-world scenario.
The vulnerability history is a clean slate, with no recorded CVEs, indicating a likely history of secure development and maintenance. This, combined with the strong code signals, suggests a generally low risk profile for this plugin. The limited attack surface, consisting solely of a single shortcode with no explicit mention of authentication checks on this specific entry point, is also a positive factor. Overall, while the plugin adheres to many security best practices, the absence of nonce checks is a point that warrants consideration in a comprehensive security assessment.
Key Concerns
- Missing nonce checks
OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System Security Vulnerabilities
OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System Release Timeline
OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System Code Analysis
Bundled Libraries
Output Escaping
OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System Maintenance & Trust
Maintenance Signals
Community Trust
OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System Alternatives
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers
popup-builder-block
Powerful Popup Builder Block for Gutenberg block editor.
Modern Cart – WooCommerce Side Cart & Popup Cart
modern-cart
Modern Cart gives your store a side cart and free shipping bar so shoppers stay on the page, spend more to unlock rewards, and check out in seconds.
Video Popup Block by WPZOOM
wpzoom-video-popup-block
Easily add a Gutenberg block to create customizable Play icon that open popups with YouTube, YouTube Shorts, TikTok, Vimeo, or MP4 videos
All In One Lightbox – Display Images, Audio, and Video in Popups
lightbox-block
Lightbox Block lets you display images, audio, video, and custom content in responsive lightbox galleries or media popups.
Modal Guten Block
modal-block
This plugin provides a Gutenberg Modal / Popup Block.
OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System Developer Profile
121 plugins · 740K total installs
How We Detect OffCanvas / Drawer – Responsive Slide-In Drawer & Popup System
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/offcanvas-block/build/admin-post.js/wp-content/plugins/offcanvas-block/build/admin-post.css/wp-content/plugins/offcanvas-block/build/admin-dashboard.js/wp-content/plugins/offcanvas-block/build/admin-dashboard.css/wp-content/plugins/offcanvas-block/offcanvas-block.phpoffcanvas-block/style.css?ver=offcanvas-block/build/admin-post.js?ver=offcanvas-block/build/admin-post.css?ver=offcanvas-block/build/admin-dashboard.js?ver=offcanvas-block/build/admin-dashboard.css?ver=HTML / DOM Fingerprints
obIsPipeChecker[offcanvas-block id=