
Spice Blocks Security & Risk Analysis
wordpress.org/plugins/spice-blocksIt is a block plugin that is compatible with all WordPress themes.
Is Spice Blocks Safe to Use in 2026?
Mostly Safe
Score 74/100Spice Blocks is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The plugin "spice-blocks" v2.0.7.7 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and a high percentage of properly escaped output, significant concerns remain. The static analysis reveals a notable attack surface with one AJAX handler lacking authentication checks. This is a critical oversight that could allow unauthorized users to trigger plugin functionality. Furthermore, the plugin's vulnerability history is concerning, with two known CVEs, one of which is currently unpatched and rated as high severity. The common vulnerability types, "Missing Authorization" and "Improper Limitation of a Pathname to a Restricted Directory," directly align with the identified unsecured AJAX handler, suggesting a recurring pattern of authorization and path-related issues. While the taint analysis shows no critical or high severity flows, the presence of an unprotected AJAX endpoint and the history of past vulnerabilities necessitate caution. The plugin has strengths in its data handling but weaknesses in access control and a history of exploitable flaws.
Key Concerns
- Unprotected AJAX handler found
- Unpatched High severity CVE
- Vulnerability history includes Missing Authorization
- Vulnerability history includes Path Traversal
Spice Blocks Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Spice Blocks <= 2.0.7.4 - Unauthenticated Arbitrary File Download
Spice Blocks <= 2.0.7.4 - Missing Authorization
Spice Blocks Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Spice Blocks Attack Surface
AJAX Handlers 4
WordPress Hooks 22
Maintenance & Trust
Spice Blocks Maintenance & Trust
Maintenance Signals
Community Trust
Spice Blocks Alternatives
GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor
gutenkit-blocks-addon
GutenKit – Ultimate no-code Gutenberg blocks to design stunning web pages and visually stunning posts in WordPress block editor.
Ultimate Blocks – 25+ Gutenberg Blocks for Block Editor
ultimate-blocks
Create Better Content With The Block Editor. Custom Blocks for Bloggers and Content Marketers.
PublishPress Blocks – Block Controls, Block Visibility, Block Permissions
advanced-gutenberg
PublishPress Blocks is your complete solution for the WordPress block editor. You can control block permissions, styles, visibility, usage and more.
BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library
blockart-blocks
Enhance the power of your WordPress editor with the dynamic Gutenberg blocks by BlockArt Blocks. Build any layout imaginable.
Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder
the-plus-addons-for-block-editor
90+ Gutenberg Blocks & AI Website Builder with 1000+ Templates. Complete Page Builder, Popup Builder, Mega Menu, Form Builder & More. No Code.
Spice Blocks Developer Profile
34 plugins · 63K total installs
How We Detect Spice Blocks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/spice-blocks/admin/assets/css/about.css/wp-content/plugins/spice-blocks/assets/all.min.css/wp-content/plugins/spice-blocks/build/free-blocks.bundle.js/wp-content/plugins/spice-blocks/assets/js/jquery.min.js/wp-content/plugins/spice-blocks/assets/css/editor.css/wp-content/plugins/spice-blocks/assets/css/animation.css/wp-content/plugins/spice-blocks/build/free-blocks.bundle.jsspice-blocks/style.css?ver=spice-blocks-freespice-blocks-editor-cssspice-blocks-animationHTML / DOM Fingerprints
spice-blocks-admin-wrapsb-adv-buttonspice-blocks-editor-wrapperwp-block-spiceblocks<!-- .wp-block --><!-- wp:spiceblocks/section --><!-- /wp:spiceblocks/section -->data-blockdata-block-headingdata-block-dividerdata-block-spacerdata-block-buttondata-block-icon+15 moreSpiceBlocksData/wp-json/spice-blocks/v1/get-blocks