Templazee – A collection of Blocks and Template Library Security & Risk Analysis

wordpress.org/plugins/templazee

Create stunning websites quickly with Templazee's user-friendly blocks and template collection.

200 active installs v1.0.2 PHP 7.0+ WP 6.5+ Updated Jun 7, 2025
blockblockseditorgutenberggutenberg-blocks
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEJul 9, 2025
Safety Verdict

Is Templazee – A collection of Blocks and Template Library Safe to Use in 2026?

Mostly Safe

Score 78/100

Templazee – A collection of Blocks and Template Library is generally safe to use. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Jul 9, 2025Updated 11mo ago
Risk Assessment

The Templazee plugin version 1.0.2 demonstrates some good security practices, particularly with its adherence to prepared statements for all SQL queries and a high percentage of properly escaped output. The absence of any critical or high-severity taint flows and no identified vulnerabilities in that category are positive indicators. Furthermore, the limited attack surface, consisting solely of AJAX handlers, is a good starting point.

However, significant concerns arise from the plugin's vulnerability history. The presence of one unpatched medium-severity vulnerability, specifically related to Missing Authorization, is a critical red flag. The fact that this vulnerability was discovered as recently as July 9, 2025, indicates a recurring issue or a failure to address past security flaws promptly. While the current static analysis shows no immediate critical threats like unsanitized paths or dangerous functions, the historical pattern of missing authorization, coupled with only two capability checks and one nonce check for its two AJAX entry points, suggests a potential for vulnerabilities in authorization logic that static analysis might not fully capture. The 100% unprotected entry points in the context of the known vulnerability type warrant careful consideration.

In conclusion, Templazee v1.0.2 has some foundational security strengths, but the unresolved medium-severity vulnerability, specifically a missing authorization issue, severely undermines its overall security posture. This historical pattern suggests a need for more robust and comprehensive authorization checks across its entry points and a commitment to promptly patching all identified vulnerabilities.

Key Concerns

  • Unpatched medium severity CVE
  • Missing authorization vulnerability history
  • Limited capability checks for AJAX entry points
  • Only one nonce check for two AJAX entry points
Vulnerabilities
1 published

Templazee – A collection of Blocks and Template Library Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-49949medium · 4.3Missing Authorization

Templazee <= 1.0.2 - Missing Authorization

Jul 9, 2025Unpatched
Version History

Templazee – A collection of Blocks and Template Library Release Timeline

v1.0.2Current1 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Templazee – A collection of Blocks and Template Library Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
32
172 escaped
Nonce Checks
1
Capability Checks
2
File Operations
14
External Requests
3
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

84% escaped204 total outputs
Attack Surface

Templazee – A collection of Blocks and Template Library Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_templazee_import_demoinc\demo.php:77
noprivwp_ajax_templazee_import_demoinc\demo.php:78
WordPress Hooks 11
actionadmin_menuinc\admin-menu\admin-menu.php:6
actionwp_enqueue_scriptsinc\block-render\breadcrumb.php:12
actionrest_api_initinc\class-rest.php:42
actionadmin_menuinc\demo.php:81
filterimport_post_meta_keyinc\importer\class-wp-import.php:79
filterhttp_request_timeoutinc\importer\class-wp-import.php:80
actionenqueue_block_editor_assetstemplazee.php:58
actionadmin_enqueue_scriptstemplazee.php:60
actionwp_enqueue_scriptstemplazee.php:62
filterblock_categories_alltemplazee.php:64
actioninittemplazee.php:74
Maintenance & Trust

Templazee – A collection of Blocks and Template Library Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 7, 2025
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

Templazee – A collection of Blocks and Template Library Developer Profile

templazee

6 plugins · 580 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Templazee – A collection of Blocks and Template Library

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/templazee/assets/css/editor-style.css/wp-content/plugins/templazee/assets/css/admin-style.css/wp-content/plugins/templazee/assets/js/admin-script.js/wp-content/plugins/templazee/assets/splide/css/splide.min.css/wp-content/plugins/templazee/assets/fontawesome/css/all.css/wp-content/plugins/templazee/assets/css/custom.css/wp-content/plugins/templazee/assets/js/match-height.js/wp-content/plugins/templazee/assets/js/accordino.js+19 more
Script Paths
/wp-content/plugins/templazee/assets/js/jquery-marquee.js/wp-content/plugins/templazee/assets/js/admin-script.js/wp-content/plugins/templazee/assets/js/match-height.js/wp-content/plugins/templazee/assets/js/accordino.js/wp-content/plugins/templazee/assets/js/jquery-marquee.js/wp-content/plugins/templazee/assets/splide/js/splide.min.js+1 more
Version Parameters
templazee/assets/css/editor-style.css?ver=templazee/assets/css/admin-style.css?ver=templazee/assets/js/admin-script.js?ver=templazee/assets/splide/css/splide.min.css?ver=4.1.4templazee/assets/fontawesome/css/all.css?ver=1.0.0templazee/assets/css/custom.css?ver=1.0.0templazee/assets/js/match-height.js?ver=templazee/assets/js/accordino.js?ver=templazee/assets/js/jquery-marquee.js?ver=templazee/assets/splide/js/splide.min.js?ver=4.1.4templazee/assets/js/custom.js?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
templazee-breadcrumb-block
Data Attributes
data-block-id
JS Globals
templazee_objectajaxfilter
FAQ

Frequently Asked Questions about Templazee – A collection of Blocks and Template Library