
Rootblox – Header & Footer Builder for Full Site Editing (FSE) Security & Risk Analysis
wordpress.org/plugins/rootbloxCreate headers and footers with multiple block patterns. Easily customize layout and style for a polished look!
Is Rootblox – Header & Footer Builder for Full Site Editing (FSE) Safe to Use in 2026?
Generally Safe
Score 100/100Rootblox – Header & Footer Builder for Full Site Editing (FSE) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'rootblox' v1.0.6 plugin exhibits a generally good security posture with several strengths. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and external HTTP requests are positive indicators. The high percentage of properly escaped output (96%) and the presence of nonce and capability checks suggest a conscious effort to implement security best practices. The lack of any recorded vulnerabilities or CVEs further reinforces this positive impression, indicating a mature and stable codebase.
However, there are notable areas of concern that warrant attention. The plugin exposes two REST API routes without permission callbacks, creating a direct attack vector for unauthenticated users. Additionally, it has six AJAX handlers, with none of them having explicit authentication checks, which is a significant security risk. While taint analysis shows no unsanitized paths, the sheer number of unprotected entry points (2 REST API, 6 AJAX) represents a substantial attack surface that could be exploited if a vulnerability were to be introduced. The bundled Freemius library, while not explicitly stated as outdated, is another potential area for scrutiny in a comprehensive security review.
In conclusion, 'rootblox' v1.0.6 is a plugin with a solid foundation in secure coding practices, evidenced by its handling of SQL, output, and lack of known vulnerabilities. The primary weaknesses lie in the unprotected AJAX handlers and REST API routes, which present immediate and exploitable attack vectors. Addressing these unprotected entry points should be the highest priority to mitigate risks.
Key Concerns
- REST API routes without permission callbacks
- AJAX handlers without authentication checks
- Bundled Freemius v1.0 library
Rootblox – Header & Footer Builder for Full Site Editing (FSE) Security Vulnerabilities
Rootblox – Header & Footer Builder for Full Site Editing (FSE) Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Rootblox – Header & Footer Builder for Full Site Editing (FSE) Attack Surface
AJAX Handlers 6
REST API Routes 2
WordPress Hooks 18
Maintenance & Trust
Rootblox – Header & Footer Builder for Full Site Editing (FSE) Maintenance & Trust
Maintenance Signals
Community Trust
Rootblox – Header & Footer Builder for Full Site Editing (FSE) Alternatives
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Page Builder Gutenberg Blocks – CoBlocks
coblocks
CoBlocks is a suite of page builder WordPress blocks for Gutenberg, with 10+ new blocks and a true page builder experience with rows and columns.
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
otter-blocks
Quickly create WordPress pages with 20+ blocks, 100+ ready-to-import designs, and advanced editor extensions. It’s website building, Lego-style!
Rootblox – Header & Footer Builder for Full Site Editing (FSE) Developer Profile
40 plugins · 32K total installs
How We Detect Rootblox – Header & Footer Builder for Full Site Editing (FSE)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rootblox/blocks/business-hours/render.phpHTML / DOM Fingerprints
cthf_roo_fs