SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Security & Risk Analysis

wordpress.org/plugins/slingblocks

A minimalist Gutenberg Block Plugin that extends Gutenberg to provide page building capabilities.

6K active installs v1.7.0 PHP 7.2+ WP 5.6+ Updated Aug 19, 2025
accordionblocksgutenbergmarketingpage-builder
97
A · Safe
CVEs total3
Unpatched0
Last CVEAug 20, 2025
Safety Verdict

Is SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Safe to Use in 2026?

Generally Safe

Score 97/100

SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

3 known CVEsLast CVE: Aug 20, 2025Updated 9mo ago
Risk Assessment

The static analysis of slingblocks v1.7.0 reveals a generally good security posture regarding common web application vulnerabilities. The absence of exposed AJAX handlers, REST API routes, shortcodes, and cron events without authentication checks significantly limits the plugin's attack surface. The code also demonstrates strong practices by using prepared statements for all SQL queries and properly escaping a high percentage of its outputs. Furthermore, the lack of file operations, external HTTP requests, and identified taint flows with unsanitized paths are positive indicators.

However, the vulnerability history presents a notable concern. With a total of 3 known CVEs, all of which are medium severity and related to Cross-site Scripting (XSS), this indicates a recurring pattern of input sanitization issues. The fact that the last vulnerability was reported in the future (2025-08-20) is likely a data anomaly, but the historical trend of XSS vulnerabilities is a significant weakness. While the current version has no unpatched CVEs, this history suggests a potential for similar vulnerabilities to be introduced if input handling is not meticulously reviewed.

In conclusion, slingblocks v1.7.0 benefits from a small attack surface and good coding practices in areas like SQL and output escaping. The primary area of concern lies in its past vulnerability history, specifically the recurring XSS issues. While the current version appears clean, the historical pattern warrants vigilance regarding input validation and sanitization in future development or updates.

Key Concerns

  • Past XSS vulnerabilities indicate potential input sanitization weaknesses.
  • No nonce checks implemented on any entry points.
  • No capability checks implemented on any entry points.
Vulnerabilities
3 published

SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2025-8607medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) <= 1.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Aug 20, 2025 Patched in 1.7.0 (1d)
CVE-2024-13675medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) <= 1.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 7, 2025 Patched in 1.6.0 (1d)
CVE-2024-38684medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) <= 1.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jul 10, 2024 Patched in 1.5.0 (9d)
Code Analysis
Analyzed Mar 16, 2026

SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
47 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped50 total outputs
Attack Surface

SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
actionwpcompatibilities\after_setup_theme\class-kadence-pro.php:12
filterrender_blockfont\fonts.php:16
filterwp_footerfont\fonts.php:17
actioninitincludes\class-render-blocks.php:45
actionwp_enqueue_scriptsincludes\class-slingblocks-frontend-css.php:55
actionplugins_loadedslingblocks.php:34
actionenqueue_block_editor_assetsslingblocks.php:59
actioninitslingblocks.php:60
filteradmin_body_classslingblocks.php:61
actionadmin_footerslingblocks.php:62
actionbody_classslingblocks.php:65
actionwp_headslingblocks.php:67
actionwp_enqueue_scriptsslingblocks.php:68
filtertemplate_includeslingblocks.php:69
filtertheme_post_templatesslingblocks.php:126
filtertheme_page_templatesslingblocks.php:127
filterblock_categoriesslingblocks.php:169
filterblock_categories_allslingblocks.php:173
actionafter_setup_themeslingblocks.php:338
Maintenance & Trust

SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 19, 2025
PHP min version7.2
Downloads36K

Community Trust

Rating100/100
Number of ratings4
Active installs6K
Developer Profile

SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Developer Profile

Aman

9 plugins · 117K total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/slingblocks/dist/slingblocks-editor.js/wp-content/plugins/slingblocks/dist/slingblocks-editor.css/wp-content/plugins/slingblocks/font/fontawesome-v4-shims.min.js/wp-content/plugins/slingblocks/font/fontawesome.min.js/wp-content/plugins/slingblocks/font/fonts.php
Script Paths
/wp-content/plugins/slingblocks/font/fontawesome-v4-shims.min.js/wp-content/plugins/slingblocks/font/fontawesome.min.js
Version Parameters
slingblocks-editor?ver=slingblocks-editor.css?ver=

HTML / DOM Fingerprints

CSS Classes
slingblocks--is-astra-themeslingblocks--is-blocksy-themeslingblocks--is-neve-themeslingblocks--is-kadence-themeslingblocks--is-storefront-themeslb-editor-width-canvasslb-editor-width-boxed
Data Attributes
data-block-id
JS Globals
slingblocks_object
Shortcode Output
[slingblocks_contact_form][slingblocks_pricing_table][slingblocks_tab][slingblocks_accordion]
FAQ

Frequently Asked Questions about SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels)