
Blade Engine Security & Risk Analysis
wordpress.org/plugins/wp-blade-engineAdds Blade functionality to your theme
Is Blade Engine Safe to Use in 2026?
Generally Safe
Score 85/100Blade Engine has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-blade-engine" v1.0.1 plugin exhibits a generally positive security posture based on the provided static analysis. There are no identified dangerous functions, external HTTP requests, or raw SQL queries, indicating good practices in these areas. The absence of known vulnerabilities in its history is also a strong indicator of a well-maintained codebase.
However, there are notable concerns. The analysis reveals that 100% of the single output detected is not properly escaped, presenting a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the plugin performs file operations, and without proper validation or sanitization, these could potentially lead to insecure file handling. The lack of nonce and capability checks across all entry points, though the attack surface is currently zero, means that if any new entry points are introduced in the future, they would be vulnerable to unauthorized actions and CSRF attacks.
In conclusion, while the plugin has a clean vulnerability history and avoids several common pitfalls, the unescaped output is a critical flaw that needs immediate attention. The file operations also warrant careful review. Addressing these specific weaknesses will significantly improve the plugin's overall security.
Key Concerns
- Unescaped output detected
- File operations present without other checks
- Missing nonce checks on entry points
- Missing capability checks on entry points
Blade Engine Security Vulnerabilities
Blade Engine Release Timeline
Blade Engine Code Analysis
Output Escaping
Blade Engine Attack Surface
Maintenance & Trust
Blade Engine Maintenance & Trust
Maintenance Signals
Community Trust
Blade Engine Alternatives
Blade
blade
Brings Laravel's great template engine, Blade, to Wordpress. Just install and start using blade in your theme.
Async JavaScript
async-javascript
Async Javascript lets you add 'async' or 'defer' attribute to scripts to exclude to help increase the performance of your WordPres …
Speculative Loading
speculation-rules
Enables browsers to speculatively prerender or prefetch pages to achieve near-instant loads based on user interaction.
BoldGrid Easy SEO – Simple and Effective SEO
boldgrid-easy-seo
Easy SEO helps you easily create keyword rich content and rank higher in the search engines.
Timber
timber-library
Helps you create themes faster with sustainable code. With Timber, you write HTML using Twig Templates http://www.upstatement.com/timber/
Blade Engine Developer Profile
2 plugins · 20 total installs
How We Detect Blade Engine
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-blade-engine/resources/css/app.css/wp-content/plugins/wp-blade-engine/resources/js/app.js/wp-content/plugins/wp-blade-engine/resources/js/app.jswp-blade-engine/resources/css/app.css?ver=wp-blade-engine/resources/js/app.js?ver=HTML / DOM Fingerprints
render_blade_viewget_rendered_blade_view