
OtFm Gutenberg Spoiler – (or FAQ) collapse block Security & Risk Analysis
wordpress.org/plugins/otfm-gutenberg-spoilerThe plugin provides in the block editor 2 types of spoilers. Need FAQ or Spoiler?
Is OtFm Gutenberg Spoiler – (or FAQ) collapse block Safe to Use in 2026?
Generally Safe
Score 85/100OtFm Gutenberg Spoiler – (or FAQ) collapse block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "otfm-gutenberg-spoiler" plugin v1.5.4 demonstrates a generally strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, indicating a minimal attack surface. The absence of dangerous functions, file operations, and external HTTP requests further contributes to this. Importantly, all observed SQL queries utilize prepared statements, a crucial security practice.
However, a significant concern arises from the output escaping. With 100% of the total outputs not being properly escaped, this plugin presents a risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users that originates from or is processed by the plugin could potentially be manipulated to inject malicious scripts. The lack of nonce and capability checks, while not immediately critical given the limited attack surface, could become a weakness if new entry points are introduced in future versions.
The plugin's vulnerability history is clean, with zero recorded CVEs. This, combined with the current clean taint analysis and absence of dangerous code signals, suggests that past development has been security-conscious. Nevertheless, the unescaped output remains a critical oversight that needs immediate attention to mitigate XSS risks and ensure a more robust security profile.
Key Concerns
- Outputs not properly escaped
- No nonce checks detected
- No capability checks detected
OtFm Gutenberg Spoiler – (or FAQ) collapse block Security Vulnerabilities
OtFm Gutenberg Spoiler – (or FAQ) collapse block Code Analysis
Output Escaping
OtFm Gutenberg Spoiler – (or FAQ) collapse block Attack Surface
WordPress Hooks 8
Maintenance & Trust
OtFm Gutenberg Spoiler – (or FAQ) collapse block Maintenance & Trust
Maintenance Signals
Community Trust
OtFm Gutenberg Spoiler – (or FAQ) collapse block Alternatives
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Page Builder Gutenberg Blocks – CoBlocks
coblocks
CoBlocks is a suite of page builder WordPress blocks for Gutenberg, with 10+ new blocks and a true page builder experience with rows and columns.
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
otter-blocks
Quickly create WordPress pages with 20+ blocks, 100+ ready-to-import designs, and advanced editor extensions. It’s website building, Lego-style!
OtFm Gutenberg Spoiler – (or FAQ) collapse block Developer Profile
1 plugin · 600 total installs
How We Detect OtFm Gutenberg Spoiler – (or FAQ) collapse block
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/otfm-gutenberg-spoiler/dist/bundle.js/wp-content/plugins/otfm-gutenberg-spoiler/dist/editor-style.css/wp-content/plugins/otfm-gutenberg-spoiler/res/otfm-spoiler-min.js/wp-content/plugins/otfm-gutenberg-spoiler/res/otfm-spoiler-min.css/wp-content/plugins/otfm-gutenberg-spoiler/dist/bundle.js/wp-content/plugins/otfm-gutenberg-spoiler/res/otfm-spoiler-min.jsHTML / DOM Fingerprints
otfm-sp__otfm-sp__titlejs-otfm-sp-box__closedotfm-sp_end<!--
⌂ ⍟ ⌂ ⍟ ⌂ ⍟
⌂ ⍟ ⌂ ⍟ ⌂ ⍟ https://otshelnik-fm.ru
⌂ ⍟ ⌂ ⍟ ⌂ ⍟
--><!-- admin inline --><!-- languages --><!-- critical css before jquery ready event -->data-block="true"ogsColorogs_colors