
PDF-Preview inside File-Block Security & Risk Analysis
wordpress.org/plugins/pdf-preview-inside-file-blockExtends the core/file block to optionally insert a PDF preview image (generated by WordPress) before the file block and adds linking/lightbox options.
Is PDF-Preview inside File-Block Safe to Use in 2026?
Generally Safe
Score 100/100PDF-Preview inside File-Block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pdf-preview-inside-file-block" plugin v1.0 exhibits a generally good security posture based on the provided static analysis. The plugin has a very small attack surface, with only one AJAX handler, and crucially, this handler appears to be protected by authentication checks. The complete absence of known CVEs and vulnerability history further contributes to this positive assessment, suggesting a mature and well-maintained codebase. The plugin also demonstrates good practices by utilizing prepared statements for all SQL queries, performing capability checks, and implementing nonce checks where appropriate.
However, a significant concern arises from the output escaping. With only 48% of the 27 total outputs properly escaped, there is a notable risk of Cross-Site Scripting (XSS) vulnerabilities. If user-supplied data is not consistently sanitized before being displayed, an attacker could potentially inject malicious scripts. While the taint analysis shows no current unsanitized flows, this could be a weakness in the analysis itself or an indication that such vulnerabilities are yet to be discovered. The single file operation, while not inherently insecure, warrants attention if it involves user-controlled paths or sensitive file locations.
In conclusion, the plugin has strong foundational security elements like a limited attack surface, secure SQL handling, and proper authentication/authorization. The primary weakness lies in the insufficient output escaping, which introduces a tangible risk of XSS. The lack of historical vulnerabilities is a positive indicator, but it doesn't negate the observed code quality issues. Addressing the output escaping is the most critical step to improve the plugin's overall security.
Key Concerns
- Insufficient output escaping
PDF-Preview inside File-Block Security Vulnerabilities
PDF-Preview inside File-Block Release Timeline
PDF-Preview inside File-Block Code Analysis
Output Escaping
PDF-Preview inside File-Block Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
PDF-Preview inside File-Block Maintenance & Trust
Maintenance Signals
Community Trust
PDF-Preview inside File-Block Alternatives
Organic Profile Block
organic-profile-block
The Organic Profile Block is a custom block for the Gutenberg content editor. It displays a profile card with an image, name, title, biography, and so …
Blocks for GitHub
blocks-for-github
Easily display your GitHub profile, organization, repositories, and more within the WordPress Block Editor aka "Gutenberg".
kitpdf | WordPress Gutenberg PDF viewer blocks .
pdf-viewer-blocks
WordPress Gutenberg PDF viewer blocks helps you upload PDF and embed PDF documents to gutenberg blocks quickly and easily and PDF is viewed via Google …
BlocksBuster
blocksbuster
This plugin is a collection of blocks that will help in making WordPress sites by using Gutenberg editor. We will build more blocks in the future tha …
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
PDF-Preview inside File-Block Developer Profile
2 plugins · 0 total installs
How We Detect PDF-Preview inside File-Block
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pdf-preview-inside-file-block/editor/block-file.jsHTML / DOM Fingerprints
data-lmdm-pdf-preview-iddata-lmdm-pdf-preview-sizedata-lmdm-pdf-preview-inline-embeddata-lmdm-pdf-preview-inline-embed-heightdata-lmdm-pdf-preview-support-lightboxdata-lmdm-pdf-preview-link-to-full+2 morewindow.LMDM_PDF_PREVIEWwindow.LMDM_PDF_PREVIEW_I18N/wp-json/lmdm-pdf-preview/v1/check