
FancyPost – Post Blocks, Grids & Sliders for Block Editor and Elementor Security & Risk Analysis
wordpress.org/plugins/post-blockFancyPost provides advanced post blocks, grids, layouts, carousels, and sliders for Block Editor & Elementor. Includes featured posts and sliders.
Is FancyPost – Post Blocks, Grids & Sliders for Block Editor and Elementor Safe to Use in 2026?
Mostly Safe
Score 77/100FancyPost – Post Blocks, Grids & Sliders for Block Editor and Elementor is generally safe to use. 3 past CVEs were resolved. Keep it updated.
The 'post-block' plugin version 6.0.1 presents a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and a significant number of nonce and capability checks, there are notable areas of concern. The presence of two AJAX handlers without authentication checks creates a direct attack surface for unauthorized actions. Furthermore, the taint analysis revealing one unsanitized path, even without a critical or high severity, indicates a potential for code injection or data leakage that warrants attention.
The vulnerability history for this plugin is a significant red flag, with three known CVEs, one of which remains unpatched. The common vulnerability types of Cross-site Scripting and Missing Authorization, particularly in conjunction with the unprotected AJAX endpoints, suggest a recurring pattern of insecure handling of user input and access control. The fact that the last vulnerability was in April 2025, and it's still unpatched, implies a lack of timely security maintenance and remediation. While the plugin has strengths in its query sanitization and some security checks, the unpatched vulnerability and the unprotected entry points significantly elevate the overall risk.
Key Concerns
- Unprotected AJAX handlers
- Unsanitized path in taint analysis
- Unpatched CVE history
- Medium severity CVEs in history
FancyPost – Post Blocks, Grids & Sliders for Block Editor and Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
FancyPost <= 6.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor <= 6.0.0 - Missing Authorization to Authenticated (Subscriber+) Shortcode Export
FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor <= 5.3.1 - Authenticated (Author+) Stored Cross-Site Scripting
FancyPost – Post Blocks, Grids & Sliders for Block Editor and Elementor Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
FancyPost – Post Blocks, Grids & Sliders for Block Editor and Elementor Attack Surface
AJAX Handlers 8
Shortcodes 1
WordPress Hooks 53
Maintenance & Trust
FancyPost – Post Blocks, Grids & Sliders for Block Editor and Elementor Maintenance & Trust
Maintenance Signals
Community Trust
FancyPost – Post Blocks, Grids & Sliders for Block Editor and Elementor Alternatives
Smart Post Block – Post Grid Gutenberg Blocks
smart-post-block
A powerful Gutenberg block plugin for post layouts, post design, news magazine layouts, and blog post styling.
WP Blog Post Layouts
wp-blog-post-layouts
Versatile plugin specially designed to create beautiful posts layouts. Fully compatible with Gutenberg and Elementor. Comes with advanced features suc …
BlogLentor – Blog Designer Pack for Elementor
bloglentor-for-elementor
Design and modify your blog with creative layouts. You can easily design your blog posts with slider, Carousel and different skins with pagination.
Guten Post Layout – An Advanced Post Grid Collection
guten-post-layout
Most advanced post grid WordPress plugin for Gutenberg. Create post grids, lists, and sliders from default posts or custom post types for WordPress.
Post Blocks & Tools
bnm-blocks
Post grid, post list, and post slider Gutenberg blocks to design blog and magazine layouts easily.
FancyPost – Post Blocks, Grids & Sliders for Block Editor and Elementor Developer Profile
7 plugins · 3K total installs
How We Detect FancyPost – Post Blocks, Grids & Sliders for Block Editor and Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-block/admin/css/post-block-admin.css/wp-content/plugins/post-block/admin/js/post-block-admin.js/wp-content/plugins/post-block/admin/css/getting-started.css/wp-content/plugins/post-block/admin/js/post-block-admin.jspost-block-admin.css?ver=post-block-admin.js?ver=HTML / DOM Fingerprints
frhd-option-bodyfrhd-setting-headerfrhd-setting-header-infofrhd-setting-header-info-contentfrhd-plugin-aboutfrhd-plugin-versionfrhd-dashboard-navfrhd-current+1 moreid="frhd-plugin-version"