
VK Blocks Security & Risk Analysis
wordpress.org/plugins/vk-blocksThis is a plugin that extends Gutenberg's blocks.
Is VK Blocks Safe to Use in 2026?
Generally Safe
Score 97/100VK Blocks has a strong security track record. Known vulnerabilities have been patched promptly.
The vk-blocks plugin version 1.117.0.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries, a high percentage of properly escaped output, and a single non-critical file operation. The absence of dangerous functions and external HTTP requests is also reassuring.
However, significant concerns arise from the attack surface analysis. All four identified REST API routes lack permission callbacks, making them potentially accessible without proper authorization. This, combined with the absence of any AJAX handlers, suggests a reliance on REST API for functionalities that might require more granular access control. The plugin's vulnerability history is also a notable weakness, with a history of six medium-severity CVEs, primarily related to Improper Access Control, Improper Authorization, and Cross-site Scripting. While there are no currently unpatched vulnerabilities, this pattern indicates past susceptibility to these common web security issues.
In conclusion, while vk-blocks has strengths in its handling of SQL and output sanitization, the unprotected REST API endpoints present a clear and immediate risk. The historical pattern of vulnerabilities, particularly in authorization and access control, reinforces the need for vigilance and suggests that these areas may be recurring weaknesses. A balanced approach would involve addressing the unprotected REST API routes while remaining aware of past vulnerability types.
Key Concerns
- REST API routes without permission callbacks
- History of 6 medium severity CVEs
VK Blocks Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
VK Blocks <= 1.94.2.2 - Missing Authorization to Sensitive Information Exposure
VK Blocks <= 1.63.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block
VK Blocks <= 1.57.0.5 - Authenticated(Contributor+) Settings Update
VK Blocks <= 1.57.0.5 - Authenticated(Contributor+) Settings Update
VK Blocks <= 1.53.0.1 - Stored (Contributor+) Cross-Site Scripting in Post
VK Blocks <= 1.53.0.1 - Stored (Contributor+) Cross-Site Scripting in Tag Edit
VK Blocks Code Analysis
Output Escaping
VK Blocks Attack Surface
REST API Routes 4
WordPress Hooks 64
Maintenance & Trust
VK Blocks Maintenance & Trust
Maintenance Signals
Community Trust
VK Blocks Alternatives
Advanced Accordion Gutenberg Block – Create Beautiful FAQs, Content Accordions & Interactive Tabs
advanced-accordion-block
Create stunning FAQ & accordion blocks. SEO-optimized, fully accessible, zero performance impact. No coding needed.
Quick and Easy FAQs
quick-and-easy-faqs
Truly a quick and easy way to add FAQs to your site.
Easy Accordion Block
easy-accordion-block
Easy Accordion Block allows you to create an accordion or a FAQs section in Gutenberg editor easily.
FAQ Block For Gutenberg
faq-block-for-gutenberg
This plugin provides a quick and easy way to add FAQ's block using Gutenberg visual editor.
FAQ Schema – Accordion, Tab, Slider & Gutenberg Block
faq-schema-ultimate
Create responsive FAQs with accordion, tabs, and slider layouts. Includes FAQ Schema markup, Gutenberg blocks, and Elementor widgets.
VK Blocks Developer Profile
8 plugins · 241K total installs
How We Detect VK Blocks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vk-blocks/build/vk-blocks-build.js/wp-content/plugins/vk-blocks/build/vk-blocks-build.css/wp-content/plugins/vk-blocks/build/vk-blocks-admin.js/wp-content/plugins/vk-blocks/build/vk-blocks-editor.css/wp-content/plugins/vk-blocks/style.css/wp-content/plugins/vk-blocks/editor.css/wp-content/plugins/vk-blocks/build/vk-blocks-build.js/wp-content/plugins/vk-blocks/build/vk-blocks-admin.js/wp-content/plugins/vk-blocks/build/vk-blocks-editor.jsvk-blocks/build/vk-blocks-build.css?ver=vk-blocks/build/vk-blocks-build.js?ver=vk-blocks/build/vk-blocks-admin.js?ver=vk-blocks/build/vk-blocks-editor.css?ver=vk-blocks/style.css?ver=vk-blocks/editor.css?ver=HTML / DOM Fingerprints
vk_blockvk_blocksvk_outer_blockvk_inner_block<!-- Progressive enhancement for Progressive enhancement --><!-- Progressive enhancement for Progressive enhancement --><!-- /Progressive enhancement --><!-- Progressive enhancement -->data-vk-blockdata-vk-block-idvk_blocks_paramsvkBlocksvkBlocksAdmin