
Query Blocks Security & Risk Analysis
wordpress.org/plugins/query-blocksThis is a collection of blocks that display WordPress posts. It includes blocks for selectively displaying posts, setting selection, pagination, and d …
Is Query Blocks Safe to Use in 2026?
Generally Safe
Score 100/100Query Blocks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'query-blocks' plugin v1.1.2 demonstrates a generally positive security posture in several key areas. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the complete output escaping indicate good coding practices. Furthermore, the plugin has no recorded vulnerabilities, suggesting a stable and well-maintained codebase. The lack of file operations and external HTTP requests also reduces potential attack vectors.
However, a significant concern arises from the static analysis, which reveals two unprotected REST API routes. This directly translates to an unprotected attack surface, as these entry points lack permission callbacks. This means any unauthenticated user could potentially interact with these routes, leading to unintended consequences or information disclosure depending on their functionality. While the taint analysis shows no unsanitized flows, the presence of unprotected REST API endpoints is a critical oversight that needs immediate attention.
In conclusion, while 'query-blocks' v1.1.2 excels in secure coding practices like prepared statements and output escaping, the two unprotected REST API routes present a clear and present risk. The vulnerability history is a strength, showing no prior issues, but it does not mitigate the immediate risk posed by the exposed entry points. Addressing these unprotected routes is paramount to improving the plugin's overall security.
Key Concerns
- REST API routes without permission callbacks
- Unprotected REST API entry points
Query Blocks Security Vulnerabilities
Query Blocks Code Analysis
SQL Query Safety
Query Blocks Attack Surface
REST API Routes 2
WordPress Hooks 7
Maintenance & Trust
Query Blocks Maintenance & Trust
Maintenance Signals
Community Trust
Query Blocks Alternatives
Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver…
acf-views
Display content with full control over selection and layout. Lightweight and compatible with any theme or page builder.
Query Loop Post Selector
query-loop-post-selector
A native query loop extension that adds a new option in the filter that allows user to specifically pick certain posts to display
WP Meta Sort Posts
wp-meta-sort-posts
This WordPress plugin allows blog admins to create pages with custom sorted lists of posts using simple queries specified in a shortcode.
Voxycure Framework
voxycure-framework
Create custom fields, blocks, and post types with no limitations. A flexible, free solution for building with custom data in WordPress.
Cherry Pick for Query Loop
cherry-pick-for-query-loop
Pick specific posts for Query Loop block and display them in your preferred order.
Query Blocks Developer Profile
9 plugins · 50 total installs
How We Detect Query Blocks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/query-blocks/build/front-module.js?wp-content/plugins/query-blocks/build/front-module.jsquery-blocks/build/front-module.js?ver=HTML / DOM Fingerprints
itmar_post_option/itmar-rest-api/v1/single-post/itmar-rest-api/v1/search