WPMozo Blocks and Addons Security & Risk Analysis

wordpress.org/plugins/wpmozo-blocks-and-addons

WPMozo Blocks and Addons is a plugin that enhances the Gutenberg editor with a collection of powerful and customizable blocks.

60 active installs v1.7.0 PHP 5.6+ WP 5.0+ Updated Dec 17, 2025
blocksgutenberggutenberg-blocksgutenberg-editorwordpress-blocks
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPMozo Blocks and Addons Safe to Use in 2026?

Generally Safe

Score 100/100

WPMozo Blocks and Addons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The plugin 'wpmozo-blocks-and-addons' v1.7.0 demonstrates a generally strong security posture based on the provided static analysis. It utilizes prepared statements for all SQL queries and exhibits excellent output escaping practices, with 99% of outputs being properly escaped. The presence of nonce and capability checks on its entry points, coupled with the absence of dangerous functions and external HTTP requests, further reinforces this positive assessment. The fact that there are no recorded vulnerabilities or CVEs, and no taint flows indicating potential injection issues, is also a significant strength.

However, there are a few areas that warrant attention. The plugin has two AJAX handlers, and while the static analysis indicates no unprotected handlers, a deeper dive into the implementation of these checks would be prudent to ensure they are robust. The presence of file operations, though not flagged as a specific concern in this analysis, can sometimes represent an attack vector if not handled with extreme care regarding user-supplied input. The absence of taint analysis results could mean that no flows were found or that the analysis was not comprehensive enough to detect subtle vulnerabilities.

Overall, the plugin appears to be well-developed from a security perspective, with a focus on core secure coding practices. The lack of historical vulnerabilities is a good indicator, but ongoing vigilance and thorough auditing of any authenticated entry points are always recommended for any plugin. The low number of entry points and the apparent good handling of them suggest a manageable risk profile.

Key Concerns

  • AJAX handlers present, requires verification of auth checks
  • File operations present, potential risk if not carefully handled
  • Taint analysis not fully conclusive (0 flows analyzed)
Vulnerabilities
None known

WPMozo Blocks and Addons Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WPMozo Blocks and Addons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
144 escaped
Nonce Checks
3
Capability Checks
2
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped146 total outputs
Attack Surface

WPMozo Blocks and Addons Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_wpmozo_bna_get_team_detailincludes\class-mozo-bna-public.php:22
noprivwp_ajax_wpmozo_bna_get_team_detailincludes\class-mozo-bna-public.php:23
WordPress Hooks 23
actionadd_meta_boxesincludes\admin\class-mozo-bna-admin.php:22
actionsave_postincludes\admin\class-mozo-bna-admin.php:25
actionsave_postincludes\admin\class-mozo-bna-admin.php:26
actionplugins_loadedincludes\class-mozo-bna-blocks-and-addons.php:210
actioninitincludes\class-mozo-bna-blocks-and-addons.php:211
actionenqueue_block_editor_assetsincludes\class-mozo-bna-blocks-and-addons.php:212
actionwp_enqueue_scriptsincludes\class-mozo-bna-blocks-and-addons.php:213
actionwp_enqueue_scriptsincludes\class-mozo-bna-blocks-and-addons.php:216
filterupload_mimesincludes\class-mozo-bna-blocks-and-addons.php:219
filterwp_theme_json_data_themeincludes\class-mozo-bna-blocks-and-addons.php:220
actionadmin_enqueue_scriptsincludes\class-mozo-bna-blocks-and-addons.php:229
actioninitincludes\class-mozo-bna-post-types.php:22
actioninitincludes\class-mozo-bna-post-types.php:23
actioninitincludes\class-mozo-bna-post-types.php:25
actioninitincludes\class-mozo-bna-post-types.php:26
filteruse_block_editor_for_post_typeincludes\class-mozo-bna-post-types.php:29
filterrest_wpmozoae-testimonial_queryincludes\class-mozo-bna-post-types.php:32
filterrest_prepare_wpmozoae-testimonialincludes\class-mozo-bna-post-types.php:33
filterrest_wpmozoae-team-member_queryincludes\class-mozo-bna-post-types.php:35
filterrest_prepare_wpmozoae-team-memberincludes\class-mozo-bna-post-types.php:36
filterblock_categories_allwpmozo-blocks-and-addons.php:79
actioninitwpmozo-blocks-and-addons.php:80
actionplugins_loadedwpmozo-blocks-and-addons.php:91
Maintenance & Trust

WPMozo Blocks and Addons Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 17, 2025
PHP min version5.6
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

WPMozo Blocks and Addons Developer Profile

Elicus

5 plugins · 410 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
14 days
View full developer profile
Detection Fingerprints

How We Detect WPMozo Blocks and Addons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpmozo-blocks-and-addons/includes/assets/css/editor/wpmozo-blocks-and-addons-editor.css/wp-content/plugins/wpmozo-blocks-and-addons/includes/assets/js/editor/editor.js/wp-content/plugins/wpmozo-blocks-and-addons/includes/assets/css/vendors/swiper-bundle.css/wp-content/plugins/wpmozo-blocks-and-addons/includes/assets/css/vendors/wpmozo-swiper.css/wp-content/plugins/wpmozo-blocks-and-addons/includes/assets/css/vendors/magnificPopup.css/wp-content/plugins/wpmozo-blocks-and-addons/includes/assets/js/vendors/swiper-bundle.js/wp-content/plugins/wpmozo-blocks-and-addons/includes/assets/css/vendors/twentytwenty.css/wp-content/plugins/wpmozo-blocks-and-addons/includes/assets/css/vendors/all-animation.css+7 more
Script Paths
https://elicus.com
Version Parameters
wpmozo-blocks-and-addons/includes/assets/css/editor/wpmozo-blocks-and-addons-editor.css?ver=wpmozo-blocks-and-addons/includes/assets/js/editor/editor.js?ver=wpmozo-blocks-and-addons/includes/assets/css/vendors/swiper-bundle.css?ver=wpmozo-blocks-and-addons/includes/assets/css/vendors/wpmozo-swiper.css?ver=wpmozo-blocks-and-addons/includes/assets/css/vendors/magnificPopup.css?ver=wpmozo-blocks-and-addons/includes/assets/js/vendors/swiper-bundle.js?ver=wpmozo-blocks-and-addons/includes/assets/css/vendors/twentytwenty.css?ver=wpmozo-blocks-and-addons/includes/assets/css/vendors/all-animation.css?ver=wpmozo-blocks-and-addons/includes/assets/js/vendors/imagesloaded.pkgd.js?ver=wpmozo-blocks-and-addons/includes/assets/js/vendors/jquery_event_move.js?ver=wpmozo-blocks-and-addons/includes/assets/js/vendors/jquery_twentytwenty.js?ver=wpmozo-blocks-and-addons/includes/assets/js/vendors/tilt-jquery.js?ver=wpmozo-blocks-and-addons/includes/assets/js/vendors/lottie.min.js?ver=wpmozo-blocks-and-addons/includes/assets/js/vendors/isotope.pkgd.js?ver=wpmozo-blocks-and-addons/includes/assets/js/vendors/magnificPopup.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpmozo-block-wrapperwpmozo-swiperwpmozo-swiper-button-nextwpmozo-swiper-button-prevwpmozo-twentytwentytwentytwenty-beforetwentytwenty-aftertwentytwenty-handle+2 more
HTML Comments
<!-- wp:wpmozo/accordion --><!-- /wp:wpmozo/accordion --><!-- wp:wpmozo/button --><!-- /wp:wpmozo/button -->+42 more
Data Attributes
data-wpmozo-blockdata-block-name
JS Globals
window.wpmozoBlocks
FAQ

Frequently Asked Questions about WPMozo Blocks and Addons