Wicked Block Builder Security & Risk Analysis

wordpress.org/plugins/wicked-block-builder

Create your own custom blocks and patterns in as little as a few minutes!

10 active installs v1.4.6 PHP 7.4+ WP 6.7+ Updated Apr 22, 2025
administrationblock-builderblocksdevelopergutenberg
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wicked Block Builder Safe to Use in 2026?

Generally Safe

Score 100/100

Wicked Block Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The Wicked Block Builder plugin v1.4.6, based on static analysis, demonstrates generally good security practices with a strong emphasis on prepared statements for SQL queries and proper output escaping. The plugin also incorporates nonces and capability checks, which are essential for securing WordPress applications. The absence of external HTTP requests and the minimal use of file operations further contribute to a relatively secure posture. However, the presence of taint analysis flows with unsanitized paths, particularly two identified as high severity, indicates a potential risk of sensitive data being mishandled or exposed. While there is no historical record of CVEs for this plugin, this does not guarantee future security, and the identified taint flow issues should be addressed promptly. The plugin's overall security is promising due to its adherence to many best practices, but the identified taint flow vulnerabilities represent a clear area for immediate improvement.

Key Concerns

  • High severity taint flow detected
  • Flows with unsanitized paths detected
Vulnerabilities
None known

Wicked Block Builder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Wicked Block Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
3
62 escaped
Nonce Checks
5
Capability Checks
7
File Operations
7
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

95% escaped65 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

5 flows3 with unsanitized paths
redirect_edit_block_to_builder (classes\class-admin.php:71)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Wicked Block Builder Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 22
filterpost_row_actionsclasses\admin\class-blocks-list.php:52
actionadmin_initclasses\admin\class-blocks-list.php:58
actionadmin_footerclasses\admin\class-blocks-list.php:63
actionpre_get_postsclasses\admin\class-blocks-list.php:64
actionadmin_menuclasses\class-admin.php:45
actionadmin_headclasses\class-admin.php:46
actionadmin_initclasses\class-admin.php:47
actionadmin_initclasses\class-admin.php:48
actionadmin_enqueue_scriptsclasses\class-admin.php:49
actionadmin_enqueue_scriptsclasses\class-admin.php:50
actionadmin_noticesclasses\class-admin.php:51
filterparent_fileclasses\class-admin.php:53
filtersubmenu_fileclasses\class-admin.php:54
actioninitclasses\class-plugin.php:27
actioninitclasses\class-plugin.php:28
actionrest_api_initclasses\class-plugin.php:29
actionenqueue_block_assetsclasses\class-plugin.php:30
actionenqueue_block_editor_assetsclasses\class-plugin.php:31
actionbefore_delete_postclasses\class-plugin.php:32
actionwp_trash_postclasses\class-plugin.php:33
filterblock_categories_allclasses\class-plugin.php:35
filterplugin_action_links_wicked-block-builder/wicked-block-builder.phpclasses\class-plugin.php:36
Maintenance & Trust

Wicked Block Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 22, 2025
PHP min version7.4
Downloads5K

Community Trust

Rating100/100
Number of ratings5
Active installs10
Developer Profile

Wicked Block Builder Developer Profile

wickedplugins

4 plugins · 21K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
353 days
View full developer profile
Detection Fingerprints

How We Detect Wicked Block Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wicked-block-builder/build/css/style.css/wp-content/plugins/wicked-block-builder/build/js/builder.js/wp-content/plugins/wicked-block-builder/build/js/editor.js/wp-content/plugins/wicked-block-builder/build/js/admin-home.js/wp-content/plugins/wicked-block-builder/build/js/admin-blocks-list.js/wp-content/plugins/wicked-block-builder/build/css/editor.css/wp-content/plugins/wicked-block-builder/build/css/admin-home.css
Script Paths
/wp-content/plugins/wicked-block-builder/build/js/builder.js/wp-content/plugins/wicked-block-builder/build/js/editor.js/wp-content/plugins/wicked-block-builder/build/js/admin-home.js/wp-content/plugins/wicked-block-builder/build/js/admin-blocks-list.js
Version Parameters
wicked-block-builder/build/css/style.css?ver=wicked-block-builder/build/js/builder.js?ver=wicked-block-builder/build/js/editor.js?ver=wicked-block-builder/build/js/admin-home.js?ver=wicked-block-builder/build/js/admin-blocks-list.js?ver=wicked-block-builder/build/css/editor.css?ver=wicked-block-builder/build/css/admin-home.css?ver=

HTML / DOM Fingerprints

CSS Classes
wbb-block-editorwbb-add-new-block-buttonwbb-block-library-modalwbb-block-controlswbb-builder-canvaswbb-admin-homewbb-block-list-tablewp-block-wbb-alert+4 more
HTML Comments
<!-- BEGIN WBB Block --><!-- END WBB Block --><!-- Wicked Block Builder - Please do not edit manually -->
Data Attributes
data-wbb-block-iddata-wbb-block-typedata-wbb-block-settings
JS Globals
WickedBlockBuilderWickedBlockBuilderAdminwpData
REST Endpoints
/wp-json/wicked-block-builder/v1/blocks/wp-json/wicked-block-builder/v1/patterns/wp-json/wicked-block-builder/v1/categories
FAQ

Frequently Asked Questions about Wicked Block Builder