
Powie's TextBlox Security & Risk Analysis
wordpress.org/plugins/textbloxCreate Textblocks and insert it into your pages using a shortcode. You can very simple update standard text
Is Powie's TextBlox Safe to Use in 2026?
Generally Safe
Score 100/100Powie's TextBlox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "textblox" plugin version 0.9.6 presents a mixed security posture. On the positive side, there are no recorded vulnerabilities (CVEs) in its history, suggesting a generally stable development. The static analysis also shows a limited attack surface with only 2 entry points, and importantly, none of these entry points are reported as unprotected. There are no indications of dangerous functions, file operations, or external HTTP requests, which are common sources of vulnerabilities.
However, significant concerns arise from the static analysis of the code. The plugin executes one SQL query that is not using prepared statements, posing a potential SQL injection risk if user-supplied data is directly incorporated into the query. Furthermore, a substantial portion of the output (0%) is not properly escaped. This is a critical security flaw, as it opens the door to Cross-Site Scripting (XSS) attacks where malicious scripts could be injected into the website and executed in the user's browser. The lack of nonce checks on the single AJAX handler is also a concern, as it could potentially allow for Cross-Site Request Forgery (CSRF) attacks.
In conclusion, while the plugin's vulnerability history is clean and its attack surface is relatively small and mostly protected, the unescaped output and the raw SQL query represent critical weaknesses that require immediate attention. The lack of nonce checks on AJAX handlers adds another layer of risk. Addressing these specific code-level issues will significantly improve the plugin's security.
Key Concerns
- Raw SQL query without prepared statements
- No output escaping
- Missing nonce check on AJAX handler
Powie's TextBlox Security Vulnerabilities
Powie's TextBlox Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Powie's TextBlox Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Powie's TextBlox Maintenance & Trust
Maintenance Signals
Community Trust
Powie's TextBlox Alternatives
Extendify
extendify
The best WordPress templates, pattern, and layout library with 1,000+ designs built for the Gutenberg block editor.
Starter Sites & Templates by Neve
templates-patterns-collection
This plugin gives you access to 100+ templates and ready-to-use starter sites. Neve theme is used for all the designs.
Qi Blocks
qi-blocks
Qi Blocks is the largest collection of Gutenberg blocks developed by Qode Interactive.
WP Accessibility
wp-accessibility
WP Accessibility fixes common accessibility issues in your WordPress site.
WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder
wdesignkit
3000+ Elementor Templates, Gutenberg Templates, Widgets Builder for Elementor, Gutenberg & Bricks, Cloud Workspace & Figma Files, 160+ Widgets Library
Powie's TextBlox Developer Profile
6 plugins · 650 total installs
How We Detect Powie's TextBlox
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/textblox/textblox_16.png/wp-content/plugins/textblox/textbloxbutton.js/wp-content/plugins/textblox/textbloxbutton.jsHTML / DOM Fingerprints
catname<!-- tb-<!-- tbend -->textblox_categorytb_version[textblox id=[textblox cat=