Developer Tools Blocker Security & Risk Analysis

wordpress.org/plugins/swiftninjapro-inspect-element-console-blocker

This plugin blocks non-admin users from using inspect element, while still allowing access those with manage_options permission.

600 active installs v3.2.1 PHP 5.2.4+ WP 3.0.1+ Updated Nov 9, 2022
blockbrowserconsoleelementinspect
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 5, 2025
Safety Verdict

Is Developer Tools Blocker Safe to Use in 2026?

Use With Caution

Score 63/100

Developer Tools Blocker has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 5, 2025Updated 3yr ago
Risk Assessment

The "swiftninjapro-inspect-element-console-blocker" plugin, version 3.2.1, exhibits a mixed security posture. While the static analysis reveals a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed without authorization, there are areas of concern. The code analysis shows a significant portion of output (31%) is not properly escaped, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is not sanitized before display. Despite the absence of critical or high-severity taint flows, the presence of a medium-severity Cross-Site Request Forgery (CSRF) vulnerability in its history, which remains unpatched, is a significant risk. The lack of any identified CSRF-specific protection mechanisms in the static analysis further exacerbates this issue. The plugin's history of a medium severity CSRF vulnerability that is still unpatched is the most pressing concern, overshadowing the otherwise clean code analysis in terms of exposed entry points. Overall, the plugin has strengths in its limited attack surface and use of prepared statements, but the unpatched CSRF vulnerability and potential for XSS due to unescaped output warrant caution.

Key Concerns

  • Unpatched medium severity CVE
  • Significant unescaped output
Vulnerabilities
1

Developer Tools Blocker Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-58818medium · 4.3Cross-Site Request Forgery (CSRF)

Developer Tools Blocker <= 3.2.1 - Cross-Site Request Forgery

Sep 5, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Developer Tools Blocker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
24 escaped
Nonce Checks
0
Capability Checks
6
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

69% escaped35 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
SwiftNinjaPro_settings_GetOption (templates\admin.php:118)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Developer Tools Blocker Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionafter_setup_thememain.php:23
actionwp_enqueue_scriptsmain.php:90
actionadmin_menuswiftninjapro-inspect-element-console-blocker.php:67
Maintenance & Trust

Developer Tools Blocker Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedNov 9, 2022
PHP min version5.2.4
Downloads15K

Community Trust

Rating84/100
Number of ratings15
Active installs600
Developer Profile

Developer Tools Blocker Developer Profile

SwiftNinjaPro

7 plugins · 710 total installs

83
trust score
Avg Security Score
84/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Developer Tools Blocker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/swiftninjapro-inspect-element-console-blocker/assets/devtools-detect.js/wp-content/plugins/swiftninjapro-inspect-element-console-blocker/assets/block-console.js/wp-content/plugins/swiftninjapro-inspect-element-console-blocker/assets/block-keys.js/wp-content/plugins/swiftninjapro-inspect-element-console-blocker/assets/block-right-click.js
Script Paths
swiftninjapro-inspect-element-console-blocker/assets/devtools-detect.jsswiftninjapro-inspect-element-console-blocker/assets/block-console.jsswiftninjapro-inspect-element-console-blocker/assets/block-keys.jsswiftninjapro-inspect-element-console-blocker/assets/block-right-click.js
Version Parameters
swiftninjapro-inspect-element-console-blocker/assets/devtools-detect.js?ver=3.0.1swiftninjapro-inspect-element-console-blocker/assets/block-console.js?ver=3.0swiftninjapro-inspect-element-console-blocker/assets/block-keys.js?ver=3.0swiftninjapro-inspect-element-console-blocker/assets/block-right-click.js?ver=3.0

HTML / DOM Fingerprints

JS Globals
window.SwiftNinjaProBlockConsoleMain
FAQ

Frequently Asked Questions about Developer Tools Blocker