
Universal Blocks – Drag & Drop Page Builder Blocks and Patterns for Gutenberg Block Editor Security & Risk Analysis
wordpress.org/plugins/universal-blocksA powerful drag-and-drop page builder plugin for Gutenberg, designed to simplify website design and content creation.
Is Universal Blocks – Drag & Drop Page Builder Blocks and Patterns for Gutenberg Block Editor Safe to Use in 2026?
Generally Safe
Score 92/100Universal Blocks – Drag & Drop Page Builder Blocks and Patterns for Gutenberg Block Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The universal-blocks plugin v1.0.2-beta exhibits a strong security posture based on the provided static analysis. The plugin has a limited attack surface with all identified entry points (AJAX handlers and REST API routes) appearing to have proper authentication and permission checks. The code also demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and not engaging in file operations or external HTTP requests. The presence of a nonce check and capability check further reinforces this positive observation. The lack of recorded vulnerabilities in its history is also a significant strength, suggesting a commitment to security or a lack of exposure. However, the analysis does highlight a minor concern regarding output escaping, where only 50% of the identified outputs are properly escaped. While no critical or high severity taint flows were detected, this partial unescaped output represents a potential avenue for cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in the unescaped outputs.
Key Concerns
- Partial unescaped output detected
Universal Blocks – Drag & Drop Page Builder Blocks and Patterns for Gutenberg Block Editor Security Vulnerabilities
Universal Blocks – Drag & Drop Page Builder Blocks and Patterns for Gutenberg Block Editor Code Analysis
Output Escaping
Universal Blocks – Drag & Drop Page Builder Blocks and Patterns for Gutenberg Block Editor Attack Surface
AJAX Handlers 2
REST API Routes 3
WordPress Hooks 20
Maintenance & Trust
Universal Blocks – Drag & Drop Page Builder Blocks and Patterns for Gutenberg Block Editor Maintenance & Trust
Maintenance Signals
Community Trust
Universal Blocks – Drag & Drop Page Builder Blocks and Patterns for Gutenberg Block Editor Alternatives
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Page Builder Gutenberg Blocks – CoBlocks
coblocks
CoBlocks is a suite of page builder WordPress blocks for Gutenberg, with 10+ new blocks and a true page builder experience with rows and columns.
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
otter-blocks
Quickly create WordPress pages with 20+ blocks, 100+ ready-to-import designs, and advanced editor extensions. It’s website building, Lego-style!
GenerateBlocks
generateblocks
A small collection of lightweight WordPress blocks that can accomplish nearly anything.
Universal Blocks – Drag & Drop Page Builder Blocks and Patterns for Gutenberg Block Editor Developer Profile
6 plugins · 110 total installs
How We Detect Universal Blocks – Drag & Drop Page Builder Blocks and Patterns for Gutenberg Block Editor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/universal-blocks/assets/css/admin.css/wp-content/plugins/universal-blocks/assets/js/admin.js/wp-content/plugins/universal-blocks/assets/js/admin.jsuniversal-blocks/assets/css/admin.css?ver=universal-blocks/assets/js/admin.js?ver=HTML / DOM Fingerprints
wppub-settings