
Premium Blocks – Gutenberg Blocks, Patterns & Templates Security & Risk Analysis
wordpress.org/plugins/premium-blocks-for-gutenbergPremium Blocks for Gutenberg: Free Gutenberg blocks packed with performance-optimized tools, global styling options, responsive controls, pre-built te …
Is Premium Blocks – Gutenberg Blocks, Patterns & Templates Safe to Use in 2026?
Generally Safe
Score 98/100Premium Blocks – Gutenberg Blocks, Patterns & Templates has a strong security track record. Known vulnerabilities have been patched promptly.
The "premium-blocks-for-gutenberg" plugin v2.3.9 presents a mixed security posture. While the plugin demonstrates several good security practices, such as 100% use of prepared statements for SQL queries and a significant majority of outputs being properly escaped, there are notable areas of concern. The presence of 3 AJAX handlers without authentication checks directly exposes these entry points to unauthenticated attackers. Furthermore, the use of the `unserialize` function is a critical risk, as it can lead to Remote Code Execution if the serialized data originates from an untrusted source. Although taint analysis did not reveal critical or high-severity flows, the 8 flows with unsanitized paths warrant attention, suggesting potential for vulnerabilities if these paths are combined with other weaknesses.
The plugin's vulnerability history, with 3 medium-severity CVEs, all related to Cross-site Scripting (XSS), indicates a recurring pattern of input sanitization weaknesses. While there are currently no unpatched CVEs, this history suggests a tendency for XSS vulnerabilities to emerge. The fact that these vulnerabilities were also medium-severity means they likely required some level of user interaction or specific conditions to be exploited, but they are still significant. The plugin benefits from a lack of bundled libraries, reducing the risk of using outdated and vulnerable third-party code. However, the substantial attack surface, particularly the unprotected AJAX endpoints, combined with the `unserialize` function and past XSS issues, necessitates careful consideration of its security.
Key Concerns
- AJAX handlers without authentication checks
- Use of dangerous function: unserialize
- Medium severity CVE history (3 total)
- Flows with unsanitized paths
Premium Blocks – Gutenberg Blocks, Patterns & Templates Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Premium Blocks – Gutenberg Blocks for WordPress <= 2.1.42 - Authenticated (Contributor+) Stored Cross-Site Scripting
Premium Blocks – Gutenberg Blocks for WordPress <= 2.1.33 - Authenticated (Contributor+) Stored Cross-Site Scripting
Premium Blocks – Gutenberg Blocks for WordPress <= 2.1.27 - Authenticated (Contributor+) Stored Cross-Site Scripting
Premium Blocks – Gutenberg Blocks, Patterns & Templates Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Premium Blocks – Gutenberg Blocks, Patterns & Templates Attack Surface
AJAX Handlers 23
WordPress Hooks 74
Scheduled Events 1
Maintenance & Trust
Premium Blocks – Gutenberg Blocks, Patterns & Templates Maintenance & Trust
Maintenance Signals
Community Trust
Premium Blocks – Gutenberg Blocks, Patterns & Templates Alternatives
Styble – Gutenberg Blocks Plugin and Page Builder Gutenberg Editor
styble
Styble enhances your Gutenberg editor with powerful and easy-to-use blocks that let you build innovative and engaging websites faster and easier.
GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor
gutenkit-blocks-addon
GutenKit – Ultimate no-code Gutenberg blocks to design stunning web pages and visually stunning posts in WordPress block editor.
Ultimate Blocks – 25+ Gutenberg Blocks for Block Editor
ultimate-blocks
Create Better Content With The Block Editor. Custom Blocks for Bloggers and Content Marketers.
PublishPress Blocks – Block Controls, Block Visibility, Block Permissions
advanced-gutenberg
PublishPress Blocks is your complete solution for the WordPress block editor. You can control block permissions, styles, visibility, usage and more.
BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library
blockart-blocks
Enhance the power of your WordPress editor with the dynamic Gutenberg blocks by BlockArt Blocks. Build any layout imaginable.
Premium Blocks – Gutenberg Blocks, Patterns & Templates Developer Profile
4 plugins · 702K total installs
How We Detect Premium Blocks – Gutenberg Blocks, Patterns & Templates
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/premium-blocks-for-gutenberg/admin/assets/dashboard.css/wp-content/plugins/premium-blocks-for-gutenberg/admin/assets/js/pb-dashboard.js/wp-content/plugins/premium-blocks-for-gutenberg/admin/assets/js/pb-dashboard.js/wp-content/plugins/premium-blocks-for-gutenberg/admin/assets/js/pb-dashboard.js?ver=1.0.0HTML / DOM Fingerprints
pb-panelpb-panel-menu-link<!-- Admin menu --><!-- Admin menu Item -->data-panel-slug="pb_panel"pbgData/wp-json/kemet/v1/add