Editor Blocks by Download Manager Security & Risk Analysis

wordpress.org/plugins/wpdm-gutenberg-blocks

Editor Blocks by Download Manager is the collection of beautiful ready-to-use custom blocks for the new Gutenberg block editor.

6K active installs v3.0.1 PHP + WP + Updated Jan 26, 2026
blocksdocument-management-plugindownload-managergutenberggutenberg-blocks
100
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 20, 2023
Safety Verdict

Is Editor Blocks by Download Manager Safe to Use in 2026?

Generally Safe

Score 100/100

Editor Blocks by Download Manager has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Feb 20, 2023Updated 3mo ago
Risk Assessment

The "wpdm-gutenberg-blocks" v3.0.1 plugin exhibits a generally good security posture based on the provided static analysis. The absence of entry points like AJAX handlers, REST API routes, and shortcodes significantly reduces the attack surface. Furthermore, the code demonstrates strong practices by avoiding dangerous functions, using prepared statements for all SQL queries, and performing file operations. The lack of external HTTP requests also contributes positively to its security.

However, there are areas for improvement. The static analysis indicates that a majority of output (37%) is not properly escaped, which could be a potential avenue for Cross-Site Scripting (XSS) vulnerabilities if user-controlled data is involved in these unescaped outputs. While taint analysis found no issues, the presence of unescaped output is a concern that should be addressed.

The vulnerability history shows one past medium-severity CVE, specifically related to Cross-Site Scripting. The fact that this CVE is currently unpatched is a significant concern, indicating that older vulnerabilities might still be present and exploitable, even if not immediately obvious from the current code snapshot. The plugin's strengths lie in its limited attack surface and secure handling of database queries, but the unaddressed XSS history and the presence of unescaped output are notable weaknesses that require attention.

Key Concerns

  • Past unpatched CVE (medium severity)
  • Significant amount of unescaped output
Vulnerabilities
1 published

Editor Blocks by Download Manager Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-22713medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Gutenberge Blocks <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodes

Feb 20, 2023 Patched in 2.1.9 (337d)
Version History

Editor Blocks by Download Manager Release Timeline

v3.0.1Current
v2.4.1
v2.2.3
v2.2.2
v2.0.71 CVE
v1.3.91 CVE
Code Analysis
Analyzed Mar 16, 2026

Editor Blocks by Download Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

63% escaped8 total outputs
Attack Surface

Editor Blocks by Download Manager Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actioninitwpdm-gutenberg-blocks.php:62
actioninitwpdm-gutenberg-blocks.php:63
actionadmin_headwpdm-gutenberg-blocks.php:64
actionenqueue_block_assetswpdm-gutenberg-blocks.php:65
actionenqueue_block_editor_assetswpdm-gutenberg-blocks.php:66
filterblock_categories_allwpdm-gutenberg-blocks.php:67
Maintenance & Trust

Editor Blocks by Download Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 26, 2026
PHP min version
Downloads180K

Community Trust

Rating100/100
Number of ratings1
Active installs6K
Developer Profile

Editor Blocks by Download Manager Developer Profile

Shahjada

6 plugins · 116K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
727 days
View full developer profile
Detection Fingerprints

How We Detect Editor Blocks by Download Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpdm-gutenberg-blocks/css/block-front.css/wp-content/plugins/wpdm-gutenberg-blocks/build/style.css/wp-content/plugins/wpdm-gutenberg-blocks/build/index.js/wp-content/plugins/wpdm-gutenberg-blocks/build/editor.css
Script Paths
/wp-content/plugins/wpdm-gutenberg-blocks/build/index.js
Version Parameters
wpdm-gutenberg-blocks/css/block-front.css?ver=wpdm-gutenberg-blocks/build/style.css?ver=wpdm-gutenberg-blocks/build/index.js?ver=wpdm-gutenberg-blocks/build/editor.css?ver=

HTML / DOM Fingerprints

JS Globals
wpdmgb_route_basewpdm_categories__wpdm_roles
REST Endpoints
/wp-json/wpdm-gblocks/
FAQ

Frequently Asked Questions about Editor Blocks by Download Manager