
SB Chart block Security & Risk Analysis
wordpress.org/plugins/sb-chart-blockDisplays a Chart for CSV content.
Is SB Chart block Safe to Use in 2026?
Generally Safe
Score 99/100SB Chart block has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "sb-chart-block" v1.3.1 exhibits a mixed security posture. On the positive side, the static analysis reveals excellent practices regarding SQL query sanitization and output escaping, with 100% of queries using prepared statements and all outputs being properly escaped. There are no identified dangerous functions, file operations, external HTTP requests, or bundled libraries that could introduce vulnerabilities. The attack surface is minimal, with only one shortcode identified and no AJAX handlers or REST API routes directly exposed without authentication or permission checks.
However, there are significant concerns stemming from the vulnerability history. The plugin has one known medium-severity CVE related to Cross-site Scripting (XSS). While currently unpatched vulnerabilities are zero, the existence of a past XSS vulnerability, especially one recorded as recently as April 2025, suggests a recurring weakness in input sanitization for certain components, even if not immediately apparent in the current static analysis's taint flows. The complete lack of nonce checks and capability checks across all entry points, while the static analysis reported zero unprotected entry points, is a potential area of concern. This could mean that while direct entry points are secured, deeper functions within the shortcode might not have adequate authorization, or the static analysis might have missed nuances in how the shortcode processes data.
In conclusion, the "sb-chart-block" plugin demonstrates strong foundational security practices in its code, particularly with SQL and output handling. Nonetheless, the historical medium-severity XSS vulnerability and the absence of explicit nonce and capability checks on its sole entry point indicate potential weaknesses that warrant attention and could be exploited if specific user interactions are not rigorously validated within the shortcode's execution.
Key Concerns
- Historical medium severity CVE (XSS)
- Missing nonce checks
- Missing capability checks
SB Chart block Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
SB Chart block <= 1.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via className Parameter
SB Chart block Code Analysis
Output Escaping
SB Chart block Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
SB Chart block Maintenance & Trust
Maintenance Signals
Community Trust
SB Chart block Alternatives
Chartivio
chartivio
Professional, interactive data visualization for WordPress. Create stunning charts with a live-preview editor, CSV support, and manual data entry.
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Starter Templates – AI-Powered Templates for Elementor & Gutenberg
astra-sites
The growing library of 300+ ready-to-use templates that work with all WordPress themes including Astra, Hello, OceanWP, GeneratePress and more
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
SB Chart block Developer Profile
16 plugins · 7K total installs
How We Detect SB Chart block
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sb-chart-block/build/index.js/wp-content/plugins/sb-chart-block/js/chart.umd.js/wp-content/plugins/sb-chart-block/js/chart.umd.min.js/wp-content/plugins/sb-chart-block/js/chartjs-adapter-date-fns.bundle.min.js/wp-content/plugins/sb-chart-block/build/index.jsHTML / DOM Fingerprints
wp-block-oik-sb-chartwindow.sb_chart_block[chartjs]