
Vayu Blocks – Website Builder for the Block Editor Security & Risk Analysis
wordpress.org/plugins/vayu-blocksVayu Blocks - Page Builder For Gutenberg Editor, Block Addons & FSE Templates
Is Vayu Blocks – Website Builder for the Block Editor Safe to Use in 2026?
Use With Caution
Score 66/100Vayu Blocks – Website Builder for the Block Editor has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'vayu-blocks' plugin v1.4.4 exhibits a mixed security posture. While it demonstrates good practices like a high percentage of prepared SQL statements and properly escaped output, significant concerns arise from its attack surface and vulnerability history. The presence of 3 unprotected entry points, including AJAX handlers and REST API routes lacking proper authentication or permission checks, presents an immediate risk. Furthermore, the plugin has a history of 5 known CVEs, with one critical unpatched vulnerability, pointing to recurring security weaknesses. The common vulnerability types (Missing Authorization, XSS, Improper Access Control) and the recent critical vulnerability indicate a pattern of insecure handling of user input and access controls. This plugin requires immediate attention to address the unpatched critical vulnerability and the unprotected entry points to mitigate the risk of exploitation.
Key Concerns
- Unprotected AJAX handlers (2)
- Unprotected REST API routes (1)
- Unpatched critical CVE
- Dangerous function: preg_replace(/e)
- Flows with unsanitized paths (2)
Vayu Blocks – Website Builder for the Block Editor Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Vayu Blocks <= 1.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Block Attributes
Vayu Blocks <= 1.3.1 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via containerWidth Parameter
Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce 1.0.4 - 1.2.1 - Missing Authorization to Unauthenticated Limited Arbitrary Options Update
Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
Vayu Blocks – Website Builder for the Block Editor Release Timeline
Vayu Blocks – Website Builder for the Block Editor Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Vayu Blocks – Website Builder for the Block Editor Attack Surface
AJAX Handlers 13
REST API Routes 3
WordPress Hooks 54
Maintenance & Trust
Vayu Blocks – Website Builder for the Block Editor Maintenance & Trust
Maintenance Signals
Community Trust
Vayu Blocks – Website Builder for the Block Editor Alternatives
Responsive Blocks – Page Builder for Blocks & Patterns
responsive-block-editor-addons
50+ blocks to create rich sections in the Gutenberg editor. Use professional starter block patterns & templates to create websites within minutes.
Move Addons for Elementor
move-addons
Move Addons is a WordPress plugin for Elementor page builder, is a powerful tool that helps you to make almost every possible customization to your we …
Massive Addons for Gutenberg and WordPress
massive-addons-for-wp-blocks
Massive Addons for gutenberg extension, Beautifully designed unique elements, Includes Premium quality addons For Gutenberg Page Builder.
Magnet Blocks – Block Collection for Modern Websites
magnet-blocks
Build stunning websites with premium Gutenberg blocks. Includes pricing cards, team members, animated statistics, taglines, and more.
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Vayu Blocks – Website Builder for the Block Editor Developer Profile
49 plugins · 64K total installs
How We Detect Vayu Blocks – Website Builder for the Block Editor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vayu-blocks/assets/css/frontend.css/wp-content/plugins/vayu-blocks/assets/js/frontend.js/wp-content/plugins/vayu-blocks/build/style-index.css/wp-content/plugins/vayu-blocks/build/index.js/wp-content/plugins/vayu-blocks/build/frontend.js/wp-content/plugins/vayu-blocks/assets/js/frontend.js/wp-content/plugins/vayu-blocks/build/index.js/wp-content/plugins/vayu-blocks/build/frontend.js/wp-content/plugins/vayu-blocks/assets/js/vayu-blocks-global.js/wp-content/plugins/vayu-blocks/assets/css/frontend.css?ver=/wp-content/plugins/vayu-blocks/assets/js/frontend.js?ver=/wp-content/plugins/vayu-blocks/build/style-index.css?ver=/wp-content/plugins/vayu-blocks/build/index.js?ver=/wp-content/plugins/vayu-blocks/build/frontend.js?ver=/wp-content/plugins/vayu-blocks/assets/js/vayu-blocks-global.js?ver=HTML / DOM Fingerprints
vayu-blocks-wrapvayu-blocks-containerdata-vayu-blockdata-vayu-blocks-attributevayu_blocks_dataVayuBlocksFrontend[vayu_blocks_element][vayu_pricing_table]