Rootblox – Header & Footer Builder for Full Site Editing (FSE) Security & Risk Analysis

wordpress.org/plugins/rootblox

Create headers and footers with multiple block patterns. Easily customize layout and style for a polished look!

100 active installs v1.0.6 PHP 7.3+ WP 5.8+ Updated Dec 24, 2025
blockblocksgutenberggutenberg-blocksheader-footer-builder
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Rootblox – Header & Footer Builder for Full Site Editing (FSE) Safe to Use in 2026?

Generally Safe

Score 100/100

Rootblox – Header & Footer Builder for Full Site Editing (FSE) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The 'rootblox' v1.0.6 plugin exhibits a generally good security posture with several strengths. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and external HTTP requests are positive indicators. The high percentage of properly escaped output (96%) and the presence of nonce and capability checks suggest a conscious effort to implement security best practices. The lack of any recorded vulnerabilities or CVEs further reinforces this positive impression, indicating a mature and stable codebase.

However, there are notable areas of concern that warrant attention. The plugin exposes two REST API routes without permission callbacks, creating a direct attack vector for unauthenticated users. Additionally, it has six AJAX handlers, with none of them having explicit authentication checks, which is a significant security risk. While taint analysis shows no unsanitized paths, the sheer number of unprotected entry points (2 REST API, 6 AJAX) represents a substantial attack surface that could be exploited if a vulnerability were to be introduced. The bundled Freemius library, while not explicitly stated as outdated, is another potential area for scrutiny in a comprehensive security review.

In conclusion, 'rootblox' v1.0.6 is a plugin with a solid foundation in secure coding practices, evidenced by its handling of SQL, output, and lack of known vulnerabilities. The primary weaknesses lie in the unprotected AJAX handlers and REST API routes, which present immediate and exploitable attack vectors. Addressing these unprotected entry points should be the highest priority to mitigate risks.

Key Concerns

  • REST API routes without permission callbacks
  • AJAX handlers without authentication checks
  • Bundled Freemius v1.0 library
Vulnerabilities
None known

Rootblox – Header & Footer Builder for Full Site Editing (FSE) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Rootblox – Header & Footer Builder for Full Site Editing (FSE) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
25
637 escaped
Nonce Checks
4
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

96% escaped662 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
rootblox_ajax_search_result_handler (admin\functions.php:372)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Rootblox – Header & Footer Builder for Full Site Editing (FSE) Attack Surface

Entry Points8
Unprotected2

AJAX Handlers 6

authwp_ajax_rootblox_ajax_search_resultadmin\functions.php:469
noprivwp_ajax_rootblox_ajax_search_resultadmin\functions.php:470
authwp_ajax_rootblox_clear_welcome_noticeadmin\helpers\helper.php:22
noprivwp_ajax_rootblox_clear_welcome_noticeadmin\helpers\helper.php:23
authwp_ajax_rootblox_update_block_statusadmin\helpers\helper.php:97
noprivwp_ajax_rootblox_update_block_statusadmin\helpers\helper.php:98

REST API Routes 2

GET/wp-json/rootblox/v1/parse-blockcore\api\class-rootblox-api.php:68
GET/wp-json/rootblox/v1/pattern-contentcore\api\class-rootblox-api.php:78
WordPress Hooks 18
actionadmin_noticesadmin\admin-notice.php:53
filterrootblox_premium_checkadmin\functions.php:34
filterrootblox_create_mobile_menu_patternadmin\functions.php:327
filterrootblox_block_registration_statusadmin\helpers\helper.php:63
actionwp_enqueue_scriptsblocks\business-hours\render.php:217
actionwp_enqueue_scriptsblocks\contact-info\render.php:111
actionwp_enqueue_scriptsblocks\copyright-text\render.php:146
actionwp_enqueue_scriptsblocks\footer\render.php:214
actionwp_enqueue_scriptsblocks\header\render.php:694
actionrest_api_initcore\api\class-rootblox-api.php:64
actionadmin_enqueue_scriptsincludes\class-rootblox-admin.php:64
actionadmin_menuincludes\class-rootblox-admin.php:65
filterblock_categories_allincludes\class-rootblox-blocks.php:66
actioninitincludes\class-rootblox-blocks.php:68
actioninitincludes\class-rootblox-init.php:52
actionenqueue_block_editor_assetsincludes\class-rootblox-resources.php:75
actionenqueue_block_assetsincludes\class-rootblox-resources.php:76
actionwp_enqueue_scriptsincludes\class-rootblox-resources.php:138
Maintenance & Trust

Rootblox – Header & Footer Builder for Full Site Editing (FSE) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 24, 2025
PHP min version7.3
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Rootblox – Header & Footer Builder for Full Site Editing (FSE) Developer Profile

CozyThemes

40 plugins · 32K total installs

96
trust score
Avg Security Score
94/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Rootblox – Header & Footer Builder for Full Site Editing (FSE)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rootblox/blocks/business-hours/render.php

HTML / DOM Fingerprints

CSS Classes
cthf_
JS Globals
roo_fs
FAQ

Frequently Asked Questions about Rootblox – Header & Footer Builder for Full Site Editing (FSE)