Responsive Blocks – Page Builder for Blocks & Patterns Security & Risk Analysis

wordpress.org/plugins/responsive-block-editor-addons

50+ blocks to create rich sections in the Gutenberg editor. Use professional starter block patterns & templates to create websites within minutes.

4K active installs v2.2.3 PHP 5.6+ WP 5.0+ Updated Mar 12, 2026
blockblock-editorblocksgutenberg-templatespage-builder
95
A · Safe
CVEs total10
Unpatched0
Last CVEApr 20, 2026
Safety Verdict

Is Responsive Blocks – Page Builder for Blocks & Patterns Safe to Use in 2026?

Generally Safe

Score 95/100

Responsive Blocks – Page Builder for Blocks & Patterns has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

10 known CVEsLast CVE: Apr 20, 2026Updated 2mo ago
Risk Assessment

The "responsive-block-editor-addons" plugin v2.2.3 exhibits a mixed security posture. While it demonstrates strong adherence to secure coding practices such as 100% prepared statement usage for SQL queries and nearly all output being properly escaped, there are notable areas of concern. The presence of 5 unprotected entry points across AJAX handlers and REST API routes represents a significant attack surface that could be exploited if vulnerabilities exist within those specific handlers or routes. The plugin also has a history of 7 medium severity Cross-Site Scripting (XSS) vulnerabilities, with the most recent being in the future (2025-06-27), which is unusual and warrants further investigation. This history suggests a recurring pattern of input validation or output escaping issues that, while currently patched, could re-emerge if development practices do not fully address the root causes. The bundling of Lodash, without information on its version, also presents a potential risk if it's an outdated or vulnerable version. Overall, the plugin has good foundations in secure coding but requires vigilance regarding its unprotected entry points and historical vulnerability patterns.

Key Concerns

  • 5 unprotected entry points (AJAX/REST)
  • Bundled library (Lodash)
  • History of 7 medium XSS CVEs
Vulnerabilities
10 published

Responsive Blocks – Page Builder for Blocks & Patterns Security Vulnerabilities

CVEs by Year

2 CVEs in 2024
2024
5 CVEs in 2025
2025
3 CVEs in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
10

10 total CVEs

CVE-2026-6703medium · 4.3Missing Authorization

Responsive Blocks <= 2.2.1 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via AJAX Actions

Apr 20, 2026 Patched in 2.2.2 (1d)
CVE-2026-6675medium · 5.3Improper Input Validation

Responsive Blocks <= 2.2.0 - Unauthenticated Open Email Relay via REST API 'email_to' Parameter

Apr 20, 2026 Patched in 2.2.1 (1d)
CVE-2026-32543medium · 5.3Missing Authorization

Responsive Blocks – Page Builder for Blocks & Patterns <= 2.2.0 - Missing Authorization

Mar 11, 2026 Patched in 2.2.1 (9d)
CVE-2025-53202medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Responsive Blocks <= 2.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jun 27, 2025 Patched in 2.0.7 (6d)
CVE-2025-49881medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Responsive Blocks <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jun 12, 2025 Patched in 2.0.6 (6d)
CVE-2025-39578medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Responsive Blocks <= 2.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 16, 2025 Patched in 2.0.3 (6d)
CVE-2025-22697medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Responsive Blocks <= 1.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 31, 2025 Patched in 2.0.0 (4d)
CVE-2024-13732medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Responsive Blocks – WordPress Gutenberg Blocks <= 1.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via section_tag Parameter

Jan 29, 2025 Patched in 2.0.0 (1d)
CVE-2024-12268medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Responsive Blocks – WordPress Gutenberg Blocks <= 1.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 23, 2024 Patched in 1.9.8 (1d)
CVE-2024-43335medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Responsive Blocks – WordPress Gutenberg Blocks <= 1.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

Aug 16, 2024 Patched in 1.8.9 (7d)
Code Analysis
Analyzed Mar 16, 2026

Responsive Blocks – Page Builder for Blocks & Patterns Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
8 prepared
Unescaped Output
2
187 escaped
Nonce Checks
10
Capability Checks
16
File Operations
3
External Requests
6
Bundled Libraries
1

Bundled Libraries

Lodash

SQL Query Safety

100% prepared8 total queries

Output Escaping

99% escaped189 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

8 flows
rbea_blocks_toggle (includes\class-responsive-block-editor-addons.php:1730)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
5 unprotected

Responsive Blocks – Page Builder for Blocks & Patterns Attack Surface

Entry Points16
Unprotected5

AJAX Handlers 13

authwp_ajax_responsive_block_editor_post_paginationincludes\class-responsive-block-editor-addons.php:167
authwp_ajax_responsive_block_editor_cf7_shortcodeincludes\class-responsive-block-editor-addons.php:177
noprivwp_ajax_responsive_block_editor_cf7_shortcodeincludes\class-responsive-block-editor-addons.php:178
authwp_ajax_rbea_blocks_toggleincludes\class-responsive-block-editor-addons.php:184
authwp_ajax_rbea_toggle_auto_block_recoveryincludes\class-responsive-block-editor-addons.php:187
authwp_ajax_rbea_toggle_global_inherit_from_themeincludes\class-responsive-block-editor-addons.php:190
authwp_ajax_rbea_toggle_custom_cssincludes\class-responsive-block-editor-addons.php:193
authwp_ajax_rbea_toggle_template_library_buttonincludes\class-responsive-block-editor-addons.php:196
authwp_ajax_rbea_save_content_widthincludes\class-responsive-block-editor-addons.php:199
authwp_ajax_rbea_save_container_paddingincludes\class-responsive-block-editor-addons.php:202
authwp_ajax_rbea_save_container_gapincludes\class-responsive-block-editor-addons.php:205
authwp_ajax_rbea_sync_libraryincludes\class-responsive-block-editor-addons.php:208
authwp_ajax_rbea_block_templates_import_blockincludes\layout\class-rbea-block-templates.php:53

REST API Routes 3

GET/wp-json/custom/v1/responsive-pro-activation-status/includes\class-responsive-block-editor-addons.php:2107
GET/wp-json/custom/v1/pro-template-capability/includes\class-responsive-block-editor-addons.php:2117
POST/wp-json/wp/v2/rba_process_formincludes\class-responsive-block-editor-addons.php:2206
WordPress Hooks 75
actionwp_headclasses\class-responsive-block-editor-addons-frontend-styles-helper.php:64
actionwp_headclasses\class-responsive-block-editor-addons-frontend-styles-helper.php:65
actionplugins_loadedincludes\class-responsive-block-editor-addons.php:144
actionenqueue_block_assetsincludes\class-responsive-block-editor-addons.php:146
filterblock_categories_allincludes\class-responsive-block-editor-addons.php:148
actionenqueue_block_editor_assetsincludes\class-responsive-block-editor-addons.php:150
actionadmin_enqueue_scriptsincludes\class-responsive-block-editor-addons.php:152
actionadmin_enqueue_scriptsincludes\class-responsive-block-editor-addons.php:154
actionadmin_menuincludes\class-responsive-block-editor-addons.php:157
actionadmin_menuincludes\class-responsive-block-editor-addons.php:159
actionadmin_initincludes\class-responsive-block-editor-addons.php:162
actionadmin_initincludes\class-responsive-block-editor-addons.php:165
actionwp_enqueue_scriptsincludes\class-responsive-block-editor-addons.php:168
actionwp_enqueue_scriptsincludes\class-responsive-block-editor-addons.php:169
actionadmin_noticesincludes\class-responsive-block-editor-addons.php:172
actionadmin_initincludes\class-responsive-block-editor-addons.php:173
actionadmin_initincludes\class-responsive-block-editor-addons.php:174
actionadmin_initincludes\class-responsive-block-editor-addons.php:175
actioninitincludes\class-responsive-block-editor-addons.php:181
actionrest_api_initincludes\class-responsive-block-editor-addons.php:207
actionrest_api_initincludes\class-responsive-block-editor-addons.php:211
actionresponsive_register_admin_menuincludes\class-responsive-block-editor-addons.php:213
actionadmin_enqueue_scriptsincludes\class-responsive-block-editor-addons.php:216
filterplugin_row_metaincludes\class-responsive-block-editor-addons.php:219
filterallowed_block_types_allincludes\class-responsive-block-editor-addons.php:222
filterplugin_action_links_responsive-block-editor-addons/responsive-block-editor-addons.phpincludes\class-responsive-block-editor-addons.php:224
actionrender_blockincludes\class-responsive-block-editor-addons.php:227
filtercontent_save_preincludes\class-responsive-block-editor-addons.php:230
filteradmin_footer_textincludes\class-responsive-block-editor-addons.php:1390
actionrest_api_initincludes\layout\layout-endpoints.php:32
filterattachment_fields_to_editresponsive-block-editor-addons.php:62
filterattachment_fields_to_saveresponsive-block-editor-addons.php:78
filterrest_prepare_attachmentresponsive-block-editor-addons.php:88
actionwp_enqueue_scriptssrc\blocks\accordion\index.php:43
actionenqueue_block_assetssrc\blocks\content-timeline\index.php:44
actionwp_enqueue_scriptssrc\blocks\form\index.php:44
actionresponsive_block_editor_addons_enqueue_scriptssrc\blocks\form\index.php:45
filterrender_blocksrc\blocks\form\index.php:88
actionwp_enqueue_scriptssrc\blocks\gallery-masonry\index.php:41
actionthe_postsrc\blocks\gallery-masonry\index.php:42
actionresponsive_block_editor_addons_enqueue_scriptssrc\blocks\gallery-masonry\index.php:43
actionwp_enqueue_scriptssrc\blocks\image-hotspot\index.php:64
actionthe_postsrc\blocks\image-hotspot\index.php:65
actionresponsive_block_editor_addons_enqueue_scriptssrc\blocks\image-hotspot\index.php:66
actionwp_enqueue_scriptssrc\blocks\image-slider\index.php:59
actionthe_postsrc\blocks\image-slider\index.php:60
actionwp_enqueue_scriptssrc\blocks\inline-notice\index.php:31
actionthe_postsrc\blocks\inline-notice\index.php:32
actionresponsive_block_editor_addons_enqueue_scriptssrc\blocks\inline-notice\index.php:33
actioninitsrc\blocks\instagram\index.php:205
actioninitsrc\blocks\portfolio\index.php:604
actionrest_api_initsrc\blocks\portfolio\index.php:622
actionrest_api_initsrc\blocks\portfolio\index.php:680
actionwp_enqueue_scriptssrc\blocks\post-carousel\index.php:54
actionthe_postsrc\blocks\post-carousel\index.php:55
actionresponsive_block_editor_addons_enqueue_scriptssrc\blocks\post-carousel\index.php:56
actionwp_enqueue_scriptssrc\blocks\post-carousel\index.php:104
actionresponsive_block_editor_addons_enqueue_scriptssrc\blocks\post-carousel\index.php:105
actioninitsrc\blocks\post-carousel\index.php:1378
actionrest_api_initsrc\blocks\post-carousel\index.php:1438
actioninitsrc\blocks\post-grid\index.php:1225
actionrest_api_initsrc\blocks\post-grid\index.php:1285
actionrest_api_initsrc\blocks\post-grid\index.php:1414
actioninitsrc\blocks\post-timeline\index.php:1290
actionrest_api_initsrc\blocks\post-timeline\index.php:1330
actionrest_api_initsrc\blocks\post-timeline\index.php:1428
filterrender_blocksrc\blocks\table-of-contents\index.php:124
actioninitsrc\blocks\taxonomy-list\index.php:615
actionwp_enqueue_scriptssrc\blocks\testimonial-slider\index.php:65
actionthe_postsrc\blocks\testimonial-slider\index.php:66
actionresponsive_block_editor_addons_enqueue_scriptssrc\blocks\testimonial-slider\index.php:67
actionwp_enqueue_scriptssrc\blocks\testimonial-slider\index.php:133
actionresponsive_block_editor_addons_enqueue_scriptssrc\blocks\testimonial-slider\index.php:134
actionwp_enqueue_scriptssrc\blocks\testimonial-slider\index.php:163
actionwp_enqueue_scriptssrc\utils\fonts.php:24
Maintenance & Trust

Responsive Blocks – Page Builder for Blocks & Patterns Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 12, 2026
PHP min version5.6
Downloads170K

Community Trust

Rating96/100
Number of ratings16
Active installs4K
Developer Profile

Responsive Blocks – Page Builder for Blocks & Patterns Developer Profile

CyberChimps

4 plugins · 37K total installs

82
trust score
Avg Security Score
92/100
Avg Patch Time
85 days
View full developer profile
Detection Fingerprints

How We Detect Responsive Blocks – Page Builder for Blocks & Patterns

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/responsive-block-editor-addons/assets/css/editor.css/wp-content/plugins/responsive-block-editor-addons/assets/css/frontend.css/wp-content/plugins/responsive-block-editor-addons/assets/js/editor.js/wp-content/plugins/responsive-block-editor-addons/assets/js/frontend.js
Script Paths
/wp-content/plugins/responsive-block-editor-addons/assets/js/editor.js/wp-content/plugins/responsive-block-editor-addons/assets/js/frontend.js
Version Parameters
/wp-content/plugins/responsive-block-editor-addons/assets/css/editor.css?ver=/wp-content/plugins/responsive-block-editor-addons/assets/css/frontend.css?ver=/wp-content/plugins/responsive-block-editor-addons/assets/js/editor.js?ver=/wp-content/plugins/responsive-block-editor-addons/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
responsive-block-editor-addons-containerresponsive-block-editor-addons-headingresponsive-block-editor-addons-cta
Data Attributes
data-rbea-tooltip-text
JS Globals
ResponsiveBlockEditorAddons
REST Endpoints
/wp-json/responsive-block-editor-addons/v1/settings
FAQ

Frequently Asked Questions about Responsive Blocks – Page Builder for Blocks & Patterns