Zypento Blocks Security & Risk Analysis

wordpress.org/plugins/zypento-blocks

Gutenberg block library.

0 active installs v1.0.6 PHP 7.0+ WP 6.0+ Updated Feb 24, 2026
woocommerce
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEApr 21, 2026
Download
Safety Verdict

Is Zypento Blocks Safe to Use in 2026?

Mostly Safe

Score 78/100

Zypento Blocks is generally safe to use. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Apr 21, 2026Updated 2mo ago
Risk Assessment

The zypento-blocks plugin v1.0.6 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any reported CVEs and the plugin's adherence to secure coding practices, such as 100% prepared statements for SQL queries and over 97% proper output escaping, are significant strengths. The limited attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or capability checks further contributes to its robust security. No dangerous functions, file operations, or external HTTP requests were detected, minimizing potential exposure. The presence of nonce and capability checks, even with a minimal attack surface, indicates a mindful approach to security. Given the lack of any identified vulnerabilities, dangerous code patterns, or critical taint flows, the plugin appears to be well-developed from a security perspective. The vulnerability history being completely clean suggests diligent maintenance and a history of secure releases. Overall, zypento-blocks v1.0.6 presents a low-risk profile for WordPress installations.

Vulnerabilities
1 published

Zypento Blocks Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-5820medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Zypento Blocks <= 1.0.6 - Authenticated (Author+) Stored Cross-Site Scripting via Table of Contents Block

Apr 21, 2026Unpatched
Version History

Zypento Blocks Release Timeline

v1.0.6Current1 CVE
v1.0.51 CVE
v1.0.41 CVE
v1.0.31 CVE
v1.0.21 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 17, 2026

Zypento Blocks Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
62 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped64 total outputs
Attack Surface

Zypento Blocks Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionenqueue_block_editor_assetsincludes\core\class-blocks.php:48
actioninitincludes\core\class-blocks.php:49
actionwp_enqueue_scriptsincludes\core\class-frontend.php:37
actioninitincludes\features\class-simple-slider.php:37
filterzypento_blocks_js_variablesincludes\features\class-woo.php:37
actioninitincludes\features\class-woo.php:38
actionrest_api_initincludes\features\class-woo.php:39
Maintenance & Trust

Zypento Blocks Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 24, 2026
PHP min version7.0
Downloads311

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Zypento Blocks Developer Profile

sproutient

10 plugins · 90 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Zypento Blocks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zypento-blocks/assets/css/blockeditor.css/wp-content/plugins/zypento-blocks/assets/js/blockeditor.js/wp-content/plugins/zypento-blocks/assets/css/public.css/wp-content/plugins/zypento-blocks/assets/js/public.js
Script Paths
zypento-blocks/assets/js/blockeditor.jszypento-blocks/assets/js/public.js
Version Parameters
zypento-blocks/assets/css/blockeditor.css?ver=zypento-blocks/assets/js/blockeditor.js?ver=zypento-blocks/assets/css/public.css?ver=zypento-blocks/assets/js/public.js?ver=

HTML / DOM Fingerprints

JS Globals
zypentoBlocksEditorVariableszypentoBlocksJsVariables
REST Endpoints
/wp-json/zypento-blocks/v1/add-to-cart
FAQ

Frequently Asked Questions about Zypento Blocks