Universal Blocks – Drag & Drop Page Builder Blocks and Patterns for Gutenberg Block Editor Security & Risk Analysis

wordpress.org/plugins/universal-blocks

A powerful drag-and-drop page builder plugin for Gutenberg, designed to simplify website design and content creation.

0 active installs v1.0.2-beta PHP 7.4+ WP 6.7+ Updated Nov 17, 2024
blockscontent-creationdesign-toolsgutenbergpage-builder
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Universal Blocks – Drag & Drop Page Builder Blocks and Patterns for Gutenberg Block Editor Safe to Use in 2026?

Generally Safe

Score 92/100

Universal Blocks – Drag & Drop Page Builder Blocks and Patterns for Gutenberg Block Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The universal-blocks plugin v1.0.2-beta exhibits a strong security posture based on the provided static analysis. The plugin has a limited attack surface with all identified entry points (AJAX handlers and REST API routes) appearing to have proper authentication and permission checks. The code also demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and not engaging in file operations or external HTTP requests. The presence of a nonce check and capability check further reinforces this positive observation. The lack of recorded vulnerabilities in its history is also a significant strength, suggesting a commitment to security or a lack of exposure. However, the analysis does highlight a minor concern regarding output escaping, where only 50% of the identified outputs are properly escaped. While no critical or high severity taint flows were detected, this partial unescaped output represents a potential avenue for cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in the unescaped outputs.

Key Concerns

  • Partial unescaped output detected
Vulnerabilities
None known

Universal Blocks – Drag & Drop Page Builder Blocks and Patterns for Gutenberg Block Editor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Universal Blocks – Drag & Drop Page Builder Blocks and Patterns for Gutenberg Block Editor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
1 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped2 total outputs
Attack Surface

Universal Blocks – Drag & Drop Page Builder Blocks and Patterns for Gutenberg Block Editor Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 2

authwp_ajax_callback-nameapp\Ajax.php:25
noprivwp_ajax_callback-nameapp\Ajax.php:26

REST API Routes 3

GET/wp-json/universal-blocks/v1/blocksapp\Api.php:31
POST/wp-json/universal-blocks/v1/blocks/(?P<key>[\w-]+)app\Api.php:38
POST/wp-json/universal-blocks/v1/activateapp\Api.php:53
WordPress Hooks 20
actionplugins_loadedapp\Admin.php:39
actionadmin_noticesapp\Admin.php:40
actionafter_setup_themeapp\Admin.php:41
actioninitapp\Admin.php:42
actionactivated_pluginapp\Admin.php:43
actiondeactivated_pluginapp\Admin.php:44
actionadmin_headapp\Admin.php:45
actionadmin_menuapp\Admin.php:46
actionadmin_enqueue_scriptsapp\Admin.php:47
filteradmin_body_classapp\Admin.php:48
filterplugin_row_metaapp\Admin.php:50
actionrest_api_initapp\Api.php:25
actionwp_enqueue_scriptsapp\Assets.php:25
actionadmin_enqueue_scriptsapp\Assets.php:26
actionenqueue_block_assetsapp\Assets.php:27
actionenqueue_block_editor_assetsapp\Assets.php:28
actioninitapp\Blocks.php:25
filterblock_categories_allapp\Blocks.php:26
actionwp_headapp\Common.php:25
actionwp_headapp\Front.php:25
Maintenance & Trust

Universal Blocks – Drag & Drop Page Builder Blocks and Patterns for Gutenberg Block Editor Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 17, 2024
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Universal Blocks – Drag & Drop Page Builder Blocks and Patterns for Gutenberg Block Editor Developer Profile

Al Imran Akash

6 plugins · 110 total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Universal Blocks – Drag & Drop Page Builder Blocks and Patterns for Gutenberg Block Editor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/universal-blocks/assets/css/admin.css/wp-content/plugins/universal-blocks/assets/js/admin.js
Script Paths
/wp-content/plugins/universal-blocks/assets/js/admin.js
Version Parameters
universal-blocks/assets/css/admin.css?ver=universal-blocks/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wppub-settings
FAQ

Frequently Asked Questions about Universal Blocks – Drag & Drop Page Builder Blocks and Patterns for Gutenberg Block Editor