
ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns Security & Risk Analysis
wordpress.org/plugins/zoloblocksEmpowering Gutenberg block editor to help you create WordPress websites with 55+ free Advanced blocks, 300+ patterns, 100+ ready pages and more.
Is ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns Safe to Use in 2026?
Generally Safe
Score 89/100ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns has a strong security track record. Known vulnerabilities have been patched promptly.
The zoloblocks plugin v2.7.0 presents a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL query handling, with 100% of queries using prepared statements. Output escaping is also robust, with 97% of outputs properly handled. File operations and dangerous function usage are notably absent, and a substantial number of nonce and capability checks are implemented, indicating an awareness of security fundamentals.
However, significant concerns arise from the attack surface. Two AJAX handlers lack authentication checks, creating a direct pathway for unauthorized actions. While REST API routes are properly permissioned, the presence of unprotected AJAX endpoints is a critical flaw. The taint analysis revealed two flows with unsanitized paths, which, although not reaching critical or high severity in this specific scan, warrant attention as they represent potential avenues for exploitation if input validation is insufficient.
The vulnerability history is a major red flag. With a total of six known CVEs, including two high and four medium severity issues, the plugin has a pattern of security weaknesses. Common vulnerability types such as missing authorization, SSRF, XSS, and RFI suggest recurring problems with input sanitization and access control. The fact that the last vulnerability was reported in late 2025, and there are currently no unpatched CVEs, is a positive sign for this specific version, but the historical prevalence of severe issues necessitates caution and continuous monitoring.
Key Concerns
- Unprotected AJAX handlers found
- Taint flows with unsanitized paths
- History of high severity CVEs (2)
- History of medium severity CVEs (4)
ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
ZoloBlocks <= 2.3.11 - Missing Authorization
ZoloBlocks <= 2.3.11 - Missing Authorization to Unauthenticated Popup Enable/Disable
ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns <= 2.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting
ZoloBlocks <= 2.3.11 - Unauthenticated Sever-Side Request Forgery
ZoloBlocks <= 2.3.12 - Authenticated (Contributor+) Stored Cross-Site Scripting
ZoloBlocks <= 2.3.2 - Authenticated (Subscriber+) Local File Inclusion
ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns Attack Surface
AJAX Handlers 12
REST API Routes 8
WordPress Hooks 95
Maintenance & Trust
ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns Maintenance & Trust
Maintenance Signals
Community Trust
ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns Alternatives
Scheduled Content Block
scheduled-content-block
Scheduled Content Block makes creating scheduled content within blocks simple and completely hands-free.
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Superb Addons: Blocks, Patterns & Theme Designer for the Block Editor & FSE
superb-blocks
Create beautiful WordPress websites easily with 10+ blocks, 200+ patterns, 100+ pre-built pages, animations and Theme Designer. No coding needed!
ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns Developer Profile
24 plugins · 251K total installs
How We Detect ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zoloblocks/build/admin/index.js/wp-content/plugins/zoloblocks/build/admin/style-index.css/wp-content/plugins/zoloblocks/build/admin/index.css/wp-content/plugins/zoloblocks/build/admin/index.jszoloblocks/build/admin/index.js?ver=zoloblocks/build/admin/style-index.css?ver=zoloblocks/build/admin/index.css?ver=HTML / DOM Fingerprints
zolo-admin-jsdata-zolo-settingzoloBlocks/wp-json/zolo/v1/settings