
12 Step Meeting PDF Security & Risk Analysis
wordpress.org/plugins/12-step-meeting-pdf-generatorThis plugin requires '12 Step Meeting List', and allows creation of meeting list PDF
Is 12 Step Meeting PDF Safe to Use in 2026?
Generally Safe
Score 85/10012 Step Meeting PDF has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "12-step-meeting-pdf-generator" plugin v1.0.4 exhibits a mixed security posture. On the positive side, there are no known critical vulnerabilities recorded historically, and the code does not appear to utilize dangerous functions or perform file operations. SQL queries are all prepared, which is a good practice for preventing SQL injection. However, significant concerns arise from the static analysis. A substantial portion of the identified attack surface, specifically an AJAX handler, lacks authentication checks. Furthermore, a critical finding is that none of the 45 outputs are properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks on the AJAX entry point, coupled with the unescaped output, creates a dangerous combination that could allow attackers to inject malicious scripts executed with the privileges of logged-in users.
The vulnerability history being clean is a positive indicator, suggesting that past development might have been more robust or that the plugin hasn't been a significant target. However, the current static analysis reveals a pressing need for immediate attention to security practices. The presence of an unprotected AJAX endpoint and widespread unescaped output presents a clear and present danger. While the plugin avoids some common pitfalls like raw SQL queries and dangerous functions, the identified vulnerabilities are serious and could lead to account takeovers, unauthorized actions, or data breaches if exploited.
In conclusion, the plugin has strengths in its handling of SQL queries and lack of known historical CVEs. However, the current version suffers from a critical lack of output escaping and an unprotected AJAX endpoint, which significantly elevates its risk profile. Immediate remediation of these issues is strongly recommended to mitigate the substantial XSS and potential unauthorized action risks.
Key Concerns
- AJAX handler without auth checks
- All outputs unescaped
- Missing nonce checks
- Bundled outdated library (TCPDF v1.0)
12 Step Meeting PDF Security Vulnerabilities
12 Step Meeting PDF Release Timeline
12 Step Meeting PDF Code Analysis
Bundled Libraries
Output Escaping
12 Step Meeting PDF Attack Surface
AJAX Handlers 1
WordPress Hooks 2
Maintenance & Trust
12 Step Meeting PDF Maintenance & Trust
Maintenance Signals
Community Trust
12 Step Meeting PDF Alternatives
Bread
bread
A web-based tool that creates, maintains and generates a PDF meeting list from BMLT.
crouton
crouton
crouton provides a UI and more for view recovery meetings as stored in a Basic Meeting List Toolbox (BMLT) database.
BMLT WordPress Satellite
bmlt-wordpress-satellite-plugin
This is a "satellite" plugin for the Basic Meeting List Toolbox (BMLT).
List Locations BMLT
list-locations-bmlt
List Locations BMLT is a plugin that returns all unique towns or counties from your BMLT server for a given service body on your site.
Upcoming Meetings BMLT
upcoming-meetings-bmlt
Upcoming Meetings BMLT is a plugin that displays the next 'N' number of meetings from the current time on your page or in a widget using the …
12 Step Meeting PDF Developer Profile
1 plugin · 100 total installs
How We Detect 12 Step Meeting PDF
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/12-step-meeting-pdf-generator/css/styles.css/wp-content/plugins/12-step-meeting-pdf-generator/js/scripts.js12-step-meeting-pdf-generator/css/styles.css?ver=12-step-meeting-pdf-generator/js/scripts.js?ver=HTML / DOM Fingerprints
tsml_programstsml_program