
Osom Blocks Security & Risk Analysis
wordpress.org/plugins/osomblocksA Block to display a list of custom post type entries.
Is Osom Blocks Safe to Use in 2026?
Generally Safe
Score 99/100Osom Blocks has a strong security track record. Known vulnerabilities have been patched promptly.
The osomblocks v1.2.2 plugin exhibits a generally strong security posture based on the static analysis. There are no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the attack surface. The code also demonstrates good practices by using prepared statements for all SQL queries, properly escaping all output, and avoiding file operations and external HTTP requests. The absence of dangerous functions and taint analysis findings further reinforces this positive assessment.
However, the presence of a past vulnerability, specifically a medium-severity Cross-site Scripting (XSS) issue reported on 2025-06-26, is a notable concern. Although this vulnerability is listed as currently unpatched, it's important to note that the provided data for "Currently unpatched" is '0', which contradicts the "Last vulnerability" date. Assuming the '0' value is accurate, this indicates the past vulnerability has been addressed. Nevertheless, the historical existence of an XSS flaw suggests that developers should remain vigilant in input validation and output escaping, even with the current static analysis showing no issues. The lack of nonce and capability checks across the analyzed code, while not immediately exploitable due to the absence of entry points, represents a potential weakness if new entry points are introduced in future versions without proper security considerations.
In conclusion, osomblocks v1.2.2 appears to be a secure plugin with a minimal attack surface and good coding practices in place for the analyzed code. The past XSS vulnerability, if indeed patched, is a positive sign of responsiveness. The primary remaining concern is the lack of explicit nonce and capability checks, which, while not currently posing a direct threat, could become a vector for attacks if the plugin's functionality or entry points expand without corresponding security enhancements.
Key Concerns
- Lack of nonce checks
- Lack of capability checks
- Past medium severity vulnerability
Osom Blocks Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Osom Blocks <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via class_name Parameter
Osom Blocks Code Analysis
Output Escaping
Osom Blocks Attack Surface
WordPress Hooks 1
Maintenance & Trust
Osom Blocks Maintenance & Trust
Maintenance Signals
Community Trust
Osom Blocks Alternatives
Voxycure Framework
voxycure-framework
Create custom fields, blocks, and post types with no limitations. A flexible, free solution for building with custom data in WordPress.
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
GenerateBlocks
generateblocks
A small collection of lightweight WordPress blocks that can accomplish nearly anything.
Osom Blocks Developer Profile
10 plugins · 118K total installs
How We Detect Osom Blocks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/osomblocks/assets/css/main.css/wp-content/plugins/osomblocks/assets/js/blocks.js/wp-content/plugins/osomblocks/assets/js/editor.js/wp-content/plugins/osomblocks/assets/js/main.js/wp-content/plugins/osomblocks/assets/js/main.js/wp-content/plugins/osomblocks/assets/js/editor.js/wp-content/plugins/osomblocks/assets/js/blocks.jsosomblocks/assets/css/main.css?ver=osomblocks/assets/js/blocks.js?ver=osomblocks/assets/js/editor.js?ver=osomblocks/assets/js/main.js?ver=HTML / DOM Fingerprints
osomblocks-post-list<!-- wp:osom/cpt-list -->[osomblocks_cpt_list