
YOUELBLOCKS Security & Risk Analysis
wordpress.org/plugins/youelblocksCreate and manage custom forms intuitively using WordPress block editor.
Is YOUELBLOCKS Safe to Use in 2026?
Generally Safe
Score 100/100YOUELBLOCKS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "youelblocks" v1.0.2 plugin exhibits a mixed security posture. While it demonstrates good practices in output escaping (98%) and a clean vulnerability history with no recorded CVEs, there are significant concerns stemming from its attack surface and taint analysis. A substantial number of AJAX handlers (68 out of 88) lack authentication checks, presenting a wide entry point for potential unauthorized actions. Furthermore, the taint analysis reveals a concerning number of flows with unsanitized paths, including one critical and four high-severity issues, indicating potential vulnerabilities to injection attacks despite the use of prepared statements in SQL queries. The presence of the `shell_exec` function, a dangerous function, also warrants attention, as its misuse can lead to severe security breaches.
Despite the lack of historical vulnerabilities, the identified code signals and taint analysis findings cannot be ignored. The high number of unprotected AJAX endpoints is a critical weakness that could be exploited if an attacker can trigger these handlers. The presence of unsanitized paths in taint flows, particularly those with critical and high severity, suggests that data entering the plugin may not be properly validated or sanitized before being used, potentially leading to arbitrary code execution or data leakage. The plugin needs to address these areas of weakness to improve its overall security.
Key Concerns
- Unprotected AJAX handlers
- Critical severity taint flow
- High severity taint flows
- Dangerous function (shell_exec)
YOUELBLOCKS Security Vulnerabilities
YOUELBLOCKS Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
YOUELBLOCKS Attack Surface
AJAX Handlers 88
Shortcodes 4
WordPress Hooks 31
Maintenance & Trust
YOUELBLOCKS Maintenance & Trust
Maintenance Signals
Community Trust
YOUELBLOCKS Alternatives
JetFormBuilder — Dynamic Blocks Form Builder
jetformbuilder
Advanced form builder plugin for Gutenberg. Create forms from the ground up, customize the existing ones, and style them up – all in one editor.
Fluent Forms Block
fluentform-block
Fluent forms block is the extension of Fluent forms plugin. You can build advanced Contact form by Fluent form block.
Nelio Forms
nelio-forms
An intuitive form builder based on open WordPress technologies
DesignSetGo
designsetgo
Professional WordPress blocks without page builder bloat. 53 blocks + 16 universal extensions that enhance ANY block.
Giraforms – Contact Form, Booking Form, Survey & Custom Form Builder for Block Editor
giraforms
Build fast, GDPR-friendly forms in Gutenberg. Create contact, booking and survey forms with native blocks, local submissions, CSV export and strong an …
YOUELBLOCKS Developer Profile
1 plugin · 0 total installs
How We Detect YOUELBLOCKS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/youelblocks/assets/css/youelblocks-admin.css/wp-content/plugins/youelblocks/assets/js/youelblocks-admin.js/wp-content/plugins/youelblocks/assets/js/youelblocks-admin.jsyouelblocks/assets/css/youelblocks-admin.css?ver=youelblocks/assets/js/youelblocks-admin.js?ver=HTML / DOM Fingerprints
youelblocks-admin-dashboardyouelblocks-admin-sectionyouelblocks-featuresyouelblocks-quick-linksdata-youelblocks-form-idyouelblocks_admin_ajax_object[youelblocks_form_list]