
SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Security & Risk Analysis
wordpress.org/plugins/slingblocksA minimalist Gutenberg Block Plugin that extends Gutenberg to provide page building capabilities.
Is SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Safe to Use in 2026?
Generally Safe
Score 97/100SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The static analysis of slingblocks v1.7.0 reveals a generally good security posture regarding common web application vulnerabilities. The absence of exposed AJAX handlers, REST API routes, shortcodes, and cron events without authentication checks significantly limits the plugin's attack surface. The code also demonstrates strong practices by using prepared statements for all SQL queries and properly escaping a high percentage of its outputs. Furthermore, the lack of file operations, external HTTP requests, and identified taint flows with unsanitized paths are positive indicators.
However, the vulnerability history presents a notable concern. With a total of 3 known CVEs, all of which are medium severity and related to Cross-site Scripting (XSS), this indicates a recurring pattern of input sanitization issues. The fact that the last vulnerability was reported in the future (2025-08-20) is likely a data anomaly, but the historical trend of XSS vulnerabilities is a significant weakness. While the current version has no unpatched CVEs, this history suggests a potential for similar vulnerabilities to be introduced if input handling is not meticulously reviewed.
In conclusion, slingblocks v1.7.0 benefits from a small attack surface and good coding practices in areas like SQL and output escaping. The primary area of concern lies in its past vulnerability history, specifically the recurring XSS issues. While the current version appears clean, the historical pattern warrants vigilance regarding input validation and sanitization in future development or updates.
Key Concerns
- Past XSS vulnerabilities indicate potential input sanitization weaknesses.
- No nonce checks implemented on any entry points.
- No capability checks implemented on any entry points.
SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) <= 1.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) <= 1.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) <= 1.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Release Timeline
SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Code Analysis
Output Escaping
SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Attack Surface
WordPress Hooks 19
Maintenance & Trust
SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Maintenance & Trust
Maintenance Signals
Community Trust
SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Alternatives
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Page Builder Gutenberg Blocks – CoBlocks
coblocks
CoBlocks is a suite of page builder WordPress blocks for Gutenberg, with 10+ new blocks and a true page builder experience with rows and columns.
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
otter-blocks
Quickly create WordPress pages with 20+ blocks, 100+ ready-to-import designs, and advanced editor extensions. It’s website building, Lego-style!
GenerateBlocks
generateblocks
A small collection of lightweight WordPress blocks that can accomplish nearly anything.
SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Developer Profile
9 plugins · 117K total installs
How We Detect SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/slingblocks/dist/slingblocks-editor.js/wp-content/plugins/slingblocks/dist/slingblocks-editor.css/wp-content/plugins/slingblocks/font/fontawesome-v4-shims.min.js/wp-content/plugins/slingblocks/font/fontawesome.min.js/wp-content/plugins/slingblocks/font/fonts.php/wp-content/plugins/slingblocks/font/fontawesome-v4-shims.min.js/wp-content/plugins/slingblocks/font/fontawesome.min.jsslingblocks-editor?ver=slingblocks-editor.css?ver=HTML / DOM Fingerprints
slingblocks--is-astra-themeslingblocks--is-blocksy-themeslingblocks--is-neve-themeslingblocks--is-kadence-themeslingblocks--is-storefront-themeslb-editor-width-canvasslb-editor-width-boxeddata-block-idslingblocks_object[slingblocks_contact_form][slingblocks_pricing_table][slingblocks_tab][slingblocks_accordion]