
Thim Blocks Security & Risk Analysis
wordpress.org/plugins/thim-blocksThim Blocks is a plugin which supports users to build theme with Gutenberg .
Is Thim Blocks Safe to Use in 2026?
Generally Safe
Score 99/100Thim Blocks has a strong security track record. Known vulnerabilities have been patched promptly.
The "thim-blocks" v1.0.3 plugin exhibits a generally good security posture, with no apparent entry points like AJAX handlers, REST API routes, or shortcodes exposed without authentication checks. The code demonstrates strong practices regarding SQL queries, utilizing prepared statements exclusively, and a high percentage of output escaping, which is crucial for preventing cross-site scripting vulnerabilities. The presence of nonce checks and a single file operation, while not inherently a risk, suggests areas that warrant careful review for proper sanitization.
However, the plugin's vulnerability history is a significant concern. It has a known CVE related to 'Path Traversal,' indicating a past weakness in how it handled file paths. Although this specific vulnerability is listed as unpatched, the fact that it's a historical issue and not currently flagged as a critical or high risk suggests it may have been addressed or is no longer exploitable in the current version. The absence of any reported critical or high severity taint flows is a positive indicator, suggesting that the developers have likely addressed major code execution or data leakage risks in their development process.
In conclusion, while the static analysis reveals a solid foundation with many secure coding practices, the historical path traversal vulnerability cannot be entirely overlooked. The low number of capability checks could also be an area for improvement, potentially increasing the attack surface if new entry points are introduced in the future. The plugin appears to be actively maintained and has likely learned from past issues, but ongoing vigilance is always recommended.
Key Concerns
- Historical Path Traversal Vulnerability (CVE)
- Zero capability checks
- Potential risk in unescaped outputs (7% unescaped)
Thim Blocks Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Gutenberg Thim Blocks <= 1.0.1 - Authenticated (Contributor+) Arbitrary File Read via 'iconSVG' Parameter
Thim Blocks Code Analysis
Output Escaping
Thim Blocks Attack Surface
WordPress Hooks 9
Maintenance & Trust
Thim Blocks Maintenance & Trust
Maintenance Signals
Community Trust
Thim Blocks Alternatives
GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor
gutenkit-blocks-addon
GutenKit – Ultimate no-code Gutenberg blocks to design stunning web pages and visually stunning posts in WordPress block editor.
BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library
blockart-blocks
Enhance the power of your WordPress editor with the dynamic Gutenberg blocks by BlockArt Blocks. Build any layout imaginable.
Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder
the-plus-addons-for-block-editor
90+ Gutenberg Blocks & AI Website Builder with 1000+ Templates. Complete Page Builder, Popup Builder, Mega Menu, Form Builder & More. No Code.
Kenta Blocks – Responsive Blocks and block templates library
kenta-blocks
Kenta Blocks is a set of responsive blocks with powerful options and pre-designed templates library.
Grids: Layout builder for WordPress
grids
The most advanced page and layout builder for Gutenberg and the new Block Editor, with columns, rows and responsive controls.
Thim Blocks Developer Profile
21 plugins · 209K total installs
How We Detect Thim Blocks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/thim-blocks/assets/dist/fonts/tb-icon.css/wp-content/plugins/thim-blocks/assets/dist/css/frontend.css/wp-content/plugins/thim-blocks/assets/dist/css/thim-blocks.style.css/wp-content/plugins/thim-blocks/assets/dist/js/frontend.js/wp-content/plugins/thim-blocks/assets/dist/js/editor.jsthim-blocks/style.css?ver=thim-blocks/frontend.css?ver=thim-blocks/editor.js?ver=HTML / DOM Fingerprints
thim-blocks-accordionthim-blocks-accordion-icon-thim-blocks-countdownthim-blocks-progress-barthim-blocks-progress-bar-style-thim-blocks-tabsthim-blocks-tab-itemthim-blocks-tabs-nav-+7 moredata-block-typedata-accordion-contentdata-tab-iddata-tab-content-idwindow.ThimBlocksFrontend