
Yasothon Security & Risk Analysis
wordpress.org/plugins/yasothon-blocksYasothon is a cool plugin for the Pages editor that have many several blocks to custom your homepage. It is easy to use you just add block and select …
Is Yasothon Safe to Use in 2026?
Generally Safe
Score 85/100Yasothon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "yasothon-blocks" plugin v1.0.0 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities, file operations, and external HTTP requests is commendable. Furthermore, 100% of SQL queries use prepared statements, and all output is properly escaped, significantly reducing the risk of cross-site scripting (XSS) and other injection attacks. The plugin also has no recorded vulnerabilities in its history, suggesting a commitment to secure coding practices.
However, the static analysis does highlight a few areas for concern. The plugin lacks nonce checks and capability checks. While the current attack surface is small and all entry points are reportedly protected, the absence of these security mechanisms means that if any new entry points are introduced or if the existing ones are misconfigured for authentication, they could be susceptible to CSRF attacks or privilege escalation. The presence of bundled jQuery, without further information on its version, could also represent a potential risk if an outdated version is used, although no specific issues were flagged.
In conclusion, "yasothon-blocks" v1.0.0 is a well-coded plugin with a robust foundation against common web vulnerabilities. The main areas for improvement lie in implementing nonce and capability checks for enhanced protection against CSRF and unauthorized access, particularly as the plugin evolves. The lack of past vulnerabilities is a positive indicator, but continuous vigilance regarding security best practices is always recommended.
Key Concerns
- Missing nonce checks
- Missing capability checks
Yasothon Security Vulnerabilities
Yasothon Code Analysis
Bundled Libraries
Output Escaping
Yasothon Attack Surface
Shortcodes 2
WordPress Hooks 12
Maintenance & Trust
Yasothon Maintenance & Trust
Maintenance Signals
Community Trust
Yasothon Alternatives
BlockSpare — News, Magazine and Blog Addons for (Gutenberg) Block Editor
blockspare
Highly customizable Gutenberg blocks and starter templates to build blogs, magazines, and business websites. Create post grids, sliders, filters, and …
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid
magazine-blocks
A collection of dynamic post blocks to quickly build stunning news, magazine, and blog websites.
WP Magazine Modules Lite
wp-magazine-modules-lite
Ultimate plugin suitable for creating you own newspaper and magazine layouts using Gutenberg and Elementor page builder. Design magazine modules with …
Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons
gutenverse-news
Create professional news, blog, or magazine layouts with the best Gutenberg blocks editor, Full Site Editor, and ready to import template library.
WP News – WordPress News / Magazine Plugin
wp-news-magazine
WP News is a elementor 14+ addons, 6+ WordPress Default widgets For WordPress.
Yasothon Developer Profile
1 plugin · 0 total installs
How We Detect Yasothon
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yasothon-blocks/dist/blocks.style.build.css/wp-content/plugins/yasothon-blocks/dist/blocks.build.js/wp-content/plugins/yasothon-blocks/dist/blocks.editor.build.css/wp-content/plugins/yasothon-blocks/dist/blocks.build.jsHTML / DOM Fingerprints
yasothon-blocksyasothon_blocks_attributes/wp-json/yasothon/v1/posts/wp-json/yasothon/v1/posts-list-sidebar/wp-json/yasothon/v1/featured-posts/wp-json/yasothon/v1/posts-text-inner/wp-json/yasothon/v1/post-style-1/wp-json/yasothon/v1/post-style-2/wp-json/yasothon/v1/post-style-3/wp-json/yasothon/v1/post-style-4