Should I use Crocoblock?
Skip to content - crocoblock.com
Depends. Buy it if you're an agency or freelancer building directories, listings, or membership sites on WordPress and can stomach a learning curve. Skip it if you just need a simple site — a page builder or plain Gutenberg does that for far less.
Confidence
Medium. Based on ~20 public sources; many snippets truncated, limiting verbatim quotes and exact prices.
Ratings
- Value for money
- Ease of use
- Feature depth
- Support quality
- Security posture
Pricing
All-Inclusive Yearly
Not disclosed in reviewed sources
ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
All-Inclusive LifetimeNot disclosed in reviewed sources
Best for
- →Freelancers and agencies building dynamic WordPress sites
- →Directory, listing, and membership sites
- →Elementor/Gutenberg power users
- →Custom post types and filters without heavy coding
Not for
- ×Simple blogs or brochure sites — massive overkill
- ×Non-technical users wanting a one-click website
- ×Anyone unwilling to learn JetEngine's workflow
- ×Security-sensitive sites that can't patch plugins quickly
Gotchas - check before you buy
high
JetEngine <=3.1.3 had an authenticated file-upload-to-RCE flaw; updating plugins is mandatory, not optional.
medium
2025-2026 advisories span several plugins (JetTabs, JetElements, JetBlog); patch quickly after releases.
medium
Users report needing Elementor Pro alongside it — budget for both subscriptions.
low
Refunds only within 30 days and only per Terms of Use conditions.
Pros and cons
Pros
- +20+ plugin bundle covering dynamic content, forms, filters, and search
- +Works with both Elementor and Gutenberg
- +Yearly and lifetime all-inclusive plans available
- +30-day refund policy per Terms of Use
- +Runs a Patchstack security partnership and publishes a security page
Cons
- −Multiple CVEs across JetPlugins, including JetEngine RCE and code injection
- −Steep learning curve; reviews position it for 'WordPress nerds'
- −Reddit threads question whether the investment is worth it
- −Users debate also needing Elementor Pro — added cost and coupling
Sources & method
Analyzed 9/26/2026 - 12 sources - Several 2025-2026 CVEs across JetPlugins, including a JetEngine remote code execution flaw; vendor runs a Patchstack partnership and a security page.
official x3review x6security x3
- JetEngine arbitrary file upload to RCE (<=3.1.3), Authenticated (Author+) users could upload files and achieve remote code execution.
- CVE-2025-53194 — JetEngine code injection, Code injection vulnerability in JetEngine tracked in the SentinelOne vulnerability database.
- CVE-2025-54687 — JetTabs DOM-based XSS, DOM-based cross-site scripting vulnerability in JetTabs.
- CVE-2025-39447 — JetElements missing authorization, Missing authorization vulnerability in JetElements for Elementor.
- CVE-2025-68503 — JetBlog missing authorization, Missing authorization vulnerability in the JetBlog plugin.
Comments
One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.
No comments yet.