Services Section Block – Showcase Service Details in Grid or Columns Security & Risk Analysis

wordpress.org/plugins/services-section

Deliver your services beautifully to clients with Services Section Block.

2K active installs v1.4.4 PHP 7.1+ WP 6.5+ Updated Apr 9, 2026
blockour-serviceservice-cardservices-sectionservices-template
99
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 23, 2025
Safety Verdict

Is Services Section Block – Showcase Service Details in Grid or Columns Safe to Use in 2026?

Generally Safe

Score 99/100

Services Section Block – Showcase Service Details in Grid or Columns has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Feb 23, 2025Updated 1mo ago
Risk Assessment

The 'services-section' plugin v1.4.3 demonstrates strong security practices in its static analysis. All identified entry points (AJAX handlers, shortcodes) have proper authentication and capability checks, and importantly, no unprotected entry points were found. The code exhibits excellent adherence to secure coding principles, with all SQL queries using prepared statements and all output being properly escaped. The absence of dangerous functions and file operations further contributes to a positive security posture. The plugin's vulnerability history shows a single medium-severity Cross-Site Scripting (XSS) vulnerability from early 2025, which is now patched. While the current version appears secure based on this analysis, the past XSS vulnerability indicates that input sanitization and output escaping, though seemingly well-implemented now, require ongoing vigilance. The external HTTP request warrants attention, as it could potentially be a vector if the external service is compromised or if the request is not handled securely, though no specific risks are evident from the provided data.

Key Concerns

  • Past medium severity XSS vulnerability
  • External HTTP request (potential risk)
Vulnerabilities
1 published

Services Section Block – Showcase Service Details in Grid or Columns Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-26947medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Services Section block <= 1.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Feb 23, 2025 Patched in 1.3.5 (9d)
Version History

Services Section Block – Showcase Service Details in Grid or Columns Release Timeline

v1.4.4Current
v1.4.3
v1.4.2
v1.4.1
v1.4.0
v1.3.8
v1.3.7
v1.3.6
v1.3.5
v1.3.41 CVE
v1.3.31 CVE
v1.3.21 CVE
v1.3.11 CVE
v1.3.01 CVE
v1.2.91 CVE
v1.2.81 CVE
v1.2.71 CVE
v1.2.61 CVE
v1.2.51 CVE
v1.2.41 CVE
Code Analysis
Analyzed Mar 16, 2026

Services Section Block – Showcase Service Details in Grid or Columns Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
45 escaped
Nonce Checks
5
Capability Checks
6
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Freemius

Output Escaping

100% escaped45 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
fs_init (freemius-lite\inc\Base\FSActivate.php:68)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Services Section Block – Showcase Service Details in Grid or Columns Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 3

authwp_ajax_fs_initfreemius-lite\inc\Base\FSActivate.php:42
authwp_ajax_ssbPremiumCheckerincludes\ssbPlugin\inc\RestAPI.php:7
noprivwp_ajax_ssbPremiumCheckerincludes\ssbPlugin\inc\RestAPI.php:8

Shortcodes 1

[services_section] includes\ssbPlugin\inc\ShortCode.php:6
WordPress Hooks 17
actionadmin_headfreemius-lite\inc\Base\FSActivate.php:29
actionadmin_enqueue_scriptsfreemius-lite\inc\Base\FSActivate.php:30
actionadmin_menufreemius-lite\inc\Base\FSActivate.php:33
actionadmin_footerfreemius-lite\inc\Base\FSActivate.php:38
actionadmin_footerfreemius-lite\inc\Base\FSActivate.php:39
actionadmin_noticesfreemius-lite\inc\Base\FSActivate.php:44
actioninitfreemius-lite\inc\Base\FS_Lite.php:29
actionadmin_menuincludes\ssbPlugin\inc\AdminMenu.php:7
actionadmin_headincludes\ssbPlugin\inc\AdminMenu.php:8
filtermanage_services_section_posts_columnsincludes\ssbPlugin\inc\CustomColumn.php:7
actionmanage_services_section_posts_custom_columnincludes\ssbPlugin\inc\CustomColumn.php:8
actionenqueue_block_assetsincludes\ssbPlugin\inc\Enqueue.php:7
actionadmin_enqueue_scriptsincludes\ssbPlugin\inc\Enqueue.php:8
actioninitincludes\ssbPlugin\inc\Init.php:7
actionadmin_initincludes\ssbPlugin\inc\RestAPI.php:9
actionrest_api_initincludes\ssbPlugin\inc\RestAPI.php:10
actionload-plugin-editor.phpincludes\utility\functions.php:13
Maintenance & Trust

Services Section Block – Showcase Service Details in Grid or Columns Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 9, 2026
PHP min version7.1
Downloads37K

Community Trust

Rating90/100
Number of ratings4
Active installs2K
Developer Profile

Services Section Block – Showcase Service Details in Grid or Columns Developer Profile

colorlibplugins

121 plugins · 740K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
130 days
View full developer profile
Detection Fingerprints

How We Detect Services Section Block – Showcase Service Details in Grid or Columns

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/services-section/includes/assets/css/main.css/wp-content/plugins/services-section/includes/assets/js/main.js
Script Paths
/wp-content/plugins/services-section/includes/assets/js/main.js
Version Parameters
services-section/includes/assets/css/main.css?ver=services-section/includes/assets/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
ssb-services-section
HTML Comments
<!-- Services Section Block -->
Data Attributes
data-services-section-id
JS Globals
servicesSectionFrontendssb_frontend_obj
REST Endpoints
/wp-json/services-section/v1/settings
Shortcode Output
<div class="ssb-services-section" data-services-section-id=
FAQ

Frequently Asked Questions about Services Section Block – Showcase Service Details in Grid or Columns