
Spectra Gutenberg Blocks – Website Builder for the Block Editor Security & Risk Analysis
wordpress.org/plugins/ultimate-addons-for-gutenbergPower-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Is Spectra Gutenberg Blocks – Website Builder for the Block Editor Safe to Use in 2026?
Generally Safe
Score 92/100Spectra Gutenberg Blocks – Website Builder for the Block Editor has a strong security track record. Known vulnerabilities have been patched promptly.
This analysis of Ultimate Addons for Gutenberg v2.19.21 reveals a mixed security posture. While the plugin demonstrates strong adherence to some security best practices, such as using prepared statements for all SQL queries and a high percentage of properly escaped output, significant concerns remain regarding its attack surface and historical vulnerability patterns. The presence of 6 unprotected entry points across AJAX handlers and REST API routes is a notable weakness, potentially exposing the plugin to unauthorized access and actions. The taint analysis, though limited in scope, did identify one flow with unsanitized paths, which warrants further investigation as it could lead to path traversal vulnerabilities. The plugin's extensive vulnerability history, with 26 known CVEs encompassing a wide range of attack vectors like information exposure, path traversal, SSRF, CSRF, and XSS, suggests a pattern of recurring security flaws. The fact that there are currently no unpatched vulnerabilities is a positive sign, but the sheer volume and variety of past issues indicate a need for rigorous and ongoing security auditing.
Key Concerns
- Unprotected AJAX handlers (3)
- Unprotected REST API routes (3)
- Taint flow with unsanitized paths (1)
- High historical vulnerability count (26)
- One high severity historical CVE
Spectra Gutenberg Blocks – Website Builder for the Block Editor Security Vulnerabilities
CVEs by Year
Severity Breakdown
26 total CVEs
Spectra Gutenberg Blocks <= 2.19.17 - Unauthenticated Information Disclosure in Sensitive Data
Spectra <= 2.19.17 - Missing Authorization
Spectra <= 2.19.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom CSS
Spectra – WordPress Gutenberg Blocks <= 2.19.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Spectra – WordPress Gutenberg Blocks <= 2.16.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Widget
Spectra – WordPress Gutenberg Blocks <= 2.15.0 - Authenticated (Contributor+) Stored Cross-site Scripting
Spectra <= 2.13.7 - Missing Authorization via generate_ai_content
Spectra – WordPress Gutenberg Blocks <= 2.13.0 - Authenticated (Author+) Stored Cross-Site Scripting
Spectra – WordPress Gutenberg Blocks <= 2.12.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Gallery Block
Spectra – WordPress Gutenberg Blocks <= 2.12.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial Block
Spectra – WordPress Gutenberg Blocks <= 2.12.6 - Authenticated (Contributor+) Path Traversal
Spectra – WordPress Gutenberg Blocks <= 2.10.3 - Authenticated(Contributor+) Cross-Site Scripting via Custom CSS
Spectra <= 2.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Spectra <= 2.6.6 - Authenticated (Contributor+) Server-Side Request Forgery in import_wpforms
Spectra <= 2.6.6 - Missing Authorization
Spectra <= 2.6.6 - Authenticated (Contributor+) Server-Side Request Forgery in template_importer
Spectra – WordPress Gutenberg Blocks <= 2.3.1 - Cross-Site Request Forgery to Plugin Activation
Spectra – WordPress Gutenberg Blocks <= 2.3.1 - Missing Authorization Checks
Spectra – WordPress Gutenberg Blocks <= 1.14.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
Spectra – WordPress Gutenberg Blocks <= 2.3.1 - Cross-Site Request Forgery to WPForm/Blocks Import
Spectra – WordPress Gutenberg Blocks <= 2.3.1 - Missing Authorization to Captcha Setting Update
Spectra – WordPress Gutenberg Blocks <= 2.3.1 - HTML Injection in Emails
Spectra – WordPress Gutenberg Blocks <= 2.3.1 - Email Spoofing
Spectra – WordPress Gutenberg Blocks <= 2.3.1 - Captcha Bypass
Spectra – WordPress Gutenberg Blocks <= 1.25.5 - Reflected Cross-Site Scripting
Spectra – WordPress Gutenberg Blocks <= 1.14.7 - Missing Authorization
Spectra Gutenberg Blocks – Website Builder for the Block Editor Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Spectra Gutenberg Blocks – Website Builder for the Block Editor Attack Surface
AJAX Handlers 30
REST API Routes 3
Shortcodes 1
WordPress Hooks 122
Scheduled Events 2
Maintenance & Trust
Spectra Gutenberg Blocks – Website Builder for the Block Editor Maintenance & Trust
Maintenance Signals
Community Trust
Spectra Gutenberg Blocks – Website Builder for the Block Editor Alternatives
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Superb Addons: Blocks, Patterns & Theme Designer for the Block Editor & FSE
superb-blocks
Create beautiful WordPress websites easily with 10+ blocks, 200+ patterns, 100+ pre-built pages, animations and Theme Designer. No coding needed!
GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor
gutenkit-blocks-addon
GutenKit – Ultimate no-code Gutenberg blocks to design stunning web pages and visually stunning posts in WordPress block editor.
Getwid – Gutenberg Blocks
getwid
40+ Gutenberg Blocks, plus multiple pre-made free block templates for the WordPress block editor.
Spectra Gutenberg Blocks – Website Builder for the Block Editor Developer Profile
32 plugins · 8.6M total installs
How We Detect Spectra Gutenberg Blocks – Website Builder for the Block Editor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ultimate-addons-for-gutenberg/assets/css/common.css/wp-content/plugins/ultimate-addons-for-gutenberg/assets/css/main.css/wp-content/plugins/ultimate-addons-for-gutenberg/assets/js/common.js/wp-content/plugins/ultimate-addons-for-gutenberg/assets/js/main.js/wp-content/plugins/ultimate-addons-for-gutenberg/admin-core/assets/css/admin-menu.css/wp-content/plugins/ultimate-addons-for-gutenberg/admin-core/assets/js/admin-menu.js/wp-content/plugins/ultimate-addons-for-gutenberg/assets/js/common.js/wp-content/plugins/ultimate-addons-for-gutenberg/assets/js/main.js/wp-content/plugins/ultimate-addons-for-gutenberg/admin-core/assets/js/admin-menu.jsultimate-addons-for-gutenberg/assets/css/common.css?ver=ultimate-addons-for-gutenberg/assets/css/main.css?ver=ultimate-addons-for-gutenberg/assets/js/common.js?ver=ultimate-addons-for-gutenberg/assets/js/main.js?ver=ultimate-addons-for-gutenberg/admin-core/assets/css/admin-menu.css?ver=ultimate-addons-for-gutenberg/admin-core/assets/js/admin-menu.js?ver=HTML / DOM Fingerprints
uagb-settingsuagb-settings-wrapuagb-admin-headingdata-component-iddata-post-iddata-blockuagb_blocks_infouagb_admin