SKT Blocks – Gutenberg based Page Builder Security & Risk Analysis

wordpress.org/plugins/skt-blocks

SKT Blocks lets you use the default gutenberg editor and easily create creative websites within minutes with the help of the reusable blocks that can …

1K active installs v2.6 PHP 7.4+ WP 5.0+ Updated Feb 4, 2026
blockseditorgutenberg-blockspage-builderwordpress-blocks
74
B · Generally Safe
CVEs total7
Unpatched1
Last CVESep 26, 2025
Safety Verdict

Is SKT Blocks – Gutenberg based Page Builder Safe to Use in 2026?

Mostly Safe

Score 74/100

SKT Blocks – Gutenberg based Page Builder is generally safe to use. 7 past CVEs were resolved. Keep it updated.

7 known CVEs 1 unpatched Last CVE: Sep 26, 2025Updated 1mo ago
Risk Assessment

The static analysis of skt-blocks v2.6 reveals a generally good security posture with strong adherence to best practices in several areas. The plugin demonstrates excellent SQL sanitation, with 100% of queries using prepared statements, and a high rate of output escaping, with 96% of outputs properly sanitized. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, shortcodes, cron events, and REST API routes significantly limits the potential attack surface. The presence of nonce and capability checks, though limited in count, also suggests an awareness of security mechanisms.

However, a significant concern arises from the plugin's vulnerability history. With a total of 7 known CVEs and one currently unpatched, all of medium severity, and a recent vulnerability in September 2025, this indicates a recurring pattern of exploitable flaws. The common vulnerability type being Cross-site Scripting is particularly worrying as it often arises from improper input handling, which might be an area where the 4% of unsanitized outputs could contribute. While the code analysis itself shows no critical taint flows or unsanitized paths, the historical context suggests that vulnerabilities can and do emerge, even if not immediately apparent in a single static analysis snapshot.

In conclusion, skt-blocks v2.6 exhibits strengths in its code hygiene and secure function usage. Nevertheless, the substantial number of past and unpatched vulnerabilities, particularly the medium-severity XSS issues, presents a notable risk. This history strongly suggests that the plugin has had issues with input validation or output encoding in the past, and the existence of an unpatched vulnerability is a direct and immediate security threat that requires urgent attention.

Key Concerns

  • Unpatched CVE detected
  • Multiple medium severity CVEs in history
  • 4% of outputs not properly escaped
Vulnerabilities
7

SKT Blocks – Gutenberg based Page Builder Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
6 CVEs in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
7

7 total CVEs

CVE-2025-60138medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SKT Blocks <= 2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 26, 2025Unpatched
CVE-2025-48270medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SKT Blocks <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 19, 2025 Patched in 2.3 (10d)
CVE-2025-46235medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SKT Blocks <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 22, 2025 Patched in 2.1 (9d)
CVE-2025-26998medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SKT Blocks – Gutenberg based Page Builder <= 1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 11, 2025 Patched in 1.9 (6d)
CVE-2025-3276medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SKT Blocks – Gutenberg based Page Builder <= 1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 11, 2025 Patched in 2.0 (1d)
CVE-2024-13733medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SKT Blocks – Gutenberg based Page Builder <= 1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

Feb 3, 2025 Patched in 1.8 (15d)
CVE-2024-43946medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SKT Blocks – Gutenberg based Page Builder <= 1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

Aug 26, 2024 Patched in 1.7 (52d)
Code Analysis
Analyzed Mar 16, 2026

SKT Blocks – Gutenberg based Page Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
195 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped203 total outputs
Attack Surface

SKT Blocks – Gutenberg based Page Builder Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_responsive_block_editor_post_paginationincludes\class-skt-blocks.php:78
WordPress Hooks 32
actionwp_headclasses\class-skt-blocks-frontend-styles-helper.php:68
actionwp_headclasses\class-skt-blocks-frontend-styles-helper.php:69
actionplugins_loadedincludes\class-skt-blocks.php:57
actioninitincludes\class-skt-blocks.php:59
filterblock_categories_allincludes\class-skt-blocks.php:61
actionenqueue_block_editor_assetsincludes\class-skt-blocks.php:63
actionenqueue_block_assetsincludes\class-skt-blocks.php:65
actionadmin_enqueue_scriptsincludes\class-skt-blocks.php:67
actionadmin_menuincludes\class-skt-blocks.php:70
actionadmin_initincludes\class-skt-blocks.php:73
actionadmin_initincludes\class-skt-blocks.php:76
actionwp_enqueue_scriptsincludes\class-skt-blocks.php:79
actionwp_enqueue_scriptssrc\blocks\accordion\index.php:15
actionwp_enqueue_scriptssrc\blocks\gallery-masonry\index.php:22
actionthe_postsrc\blocks\gallery-masonry\index.php:23
actionwp_enqueue_scriptssrc\blocks\image-slider\index.php:23
actionthe_postsrc\blocks\image-slider\index.php:24
actionwp_enqueue_scriptssrc\blocks\post-carousel\index.php:28
actionthe_postsrc\blocks\post-carousel\index.php:29
actionwp_enqueue_scriptssrc\blocks\post-carousel\index.php:58
actioninitsrc\blocks\post-carousel\index.php:1143
actionrest_api_initsrc\blocks\post-carousel\index.php:1203
actioninitsrc\blocks\post-grid\index.php:969
actionrest_api_initsrc\blocks\post-grid\index.php:1029
actionrest_api_initsrc\blocks\post-grid\index.php:1159
actioninitsrc\blocks\post-timeline\index.php:1105
actionrest_api_initsrc\blocks\post-timeline\index.php:1145
actionrest_api_initsrc\blocks\post-timeline\index.php:1244
actionwp_enqueue_scriptssrc\blocks\testimonial-slider\index.php:23
actionthe_postsrc\blocks\testimonial-slider\index.php:24
actionwp_enqueue_scriptssrc\blocks\testimonial-slider\index.php:53
actionwp_enqueue_scriptssrc\utils\fonts.php:19
Maintenance & Trust

SKT Blocks – Gutenberg based Page Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 4, 2026
PHP min version7.4
Downloads40K

Community Trust

Rating0/100
Number of ratings0
Active installs1K
Developer Profile

SKT Blocks – Gutenberg based Page Builder Developer Profile

sonalsinha21

153 plugins · 54K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
26 days
View full developer profile
Detection Fingerprints

How We Detect SKT Blocks – Gutenberg based Page Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/skt-blocks/build/block.css/wp-content/plugins/skt-blocks/build/editor.css/wp-content/plugins/skt-blocks/build/view.asset.php/wp-content/plugins/skt-blocks/build/index.js/wp-content/plugins/skt-blocks/build/frontend.js
Script Paths
/wp-content/plugins/skt-blocks/build/index.js
Version Parameters
skt-blocks/build/block.css?ver=skt-blocks/build/editor.css?ver=skt-blocks/build/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
skt-blocks-advanced-headingskt-blocks-call-to-actionskt-blocks-buttonskt-blocks-counterskt-blocks-testimonialskt-blocks-flip-boxskt-blocks-featureskt-blocks-tabs+2 more
Data Attributes
data-settingsdata-blockdata-post-iddata-typedata-orderdata-posts-per-page+16 more
JS Globals
window.wp.element.createElementwindow.wp.element.useStatewindow.wp.element.useEffectwindow.wp.blocks.registerBlockTypewindow.wp.components.PanelBodywindow.wp.components.SelectControl+9 more
FAQ

Frequently Asked Questions about SKT Blocks – Gutenberg based Page Builder