12 Step Meeting PDF Security & Risk Analysis

wordpress.org/plugins/12-step-meeting-pdf-generator

This plugin requires '12 Step Meeting List', and allows creation of meeting list PDF

100 active installs v1.0.4 PHP + WP 4.7+ Updated Aug 30, 2023
12-step-meeting12-step-meeting-list12-step-meetings12-stepmeeting-list
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is 12 Step Meeting PDF Safe to Use in 2026?

Generally Safe

Score 85/100

12 Step Meeting PDF has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "12-step-meeting-pdf-generator" plugin v1.0.4 exhibits a mixed security posture. On the positive side, there are no known critical vulnerabilities recorded historically, and the code does not appear to utilize dangerous functions or perform file operations. SQL queries are all prepared, which is a good practice for preventing SQL injection. However, significant concerns arise from the static analysis. A substantial portion of the identified attack surface, specifically an AJAX handler, lacks authentication checks. Furthermore, a critical finding is that none of the 45 outputs are properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks on the AJAX entry point, coupled with the unescaped output, creates a dangerous combination that could allow attackers to inject malicious scripts executed with the privileges of logged-in users.

The vulnerability history being clean is a positive indicator, suggesting that past development might have been more robust or that the plugin hasn't been a significant target. However, the current static analysis reveals a pressing need for immediate attention to security practices. The presence of an unprotected AJAX endpoint and widespread unescaped output presents a clear and present danger. While the plugin avoids some common pitfalls like raw SQL queries and dangerous functions, the identified vulnerabilities are serious and could lead to account takeovers, unauthorized actions, or data breaches if exploited.

In conclusion, the plugin has strengths in its handling of SQL queries and lack of known historical CVEs. However, the current version suffers from a critical lack of output escaping and an unprotected AJAX endpoint, which significantly elevates its risk profile. Immediate remediation of these issues is strongly recommended to mitigate the substantial XSS and potential unauthorized action risks.

Key Concerns

  • AJAX handler without auth checks
  • All outputs unescaped
  • Missing nonce checks
  • Bundled outdated library (TCPDF v1.0)
Vulnerabilities
None known

12 Step Meeting PDF Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

12 Step Meeting PDF Release Timeline

v1.0.4Current
v1.0.3
v1.0.2
v0.3.1
v0.3.0
v0.2.4
v0.2.3
v0.2.2
v0.2.1
v0.2.1a
v0.2.0
v0.1.8
v0.1.7
v0.1.6
v0.1.5
v0.1.4
v0.1.3
v0.1.2
v0.1.1
v0.1.0
Code Analysis
Analyzed Mar 16, 2026

12 Step Meeting PDF Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
45
0 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TCPDF1.0

Output Escaping

0% escaped45 total outputs
Attack Surface
1 unprotected

12 Step Meeting PDF Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_step_pdfpdf.php:4
WordPress Hooks 2
actionadmin_menuincludes\admin-menu.php:3
actionadmin_initincludes\admin-menu.php:6
Maintenance & Trust

12 Step Meeting PDF Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedAug 30, 2023
PHP min version
Downloads9K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

12 Step Meeting PDF Developer Profile

cdtoews

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect 12 Step Meeting PDF

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/12-step-meeting-pdf-generator/css/styles.css
Script Paths
/wp-content/plugins/12-step-meeting-pdf-generator/js/scripts.js
Version Parameters
12-step-meeting-pdf-generator/css/styles.css?ver=12-step-meeting-pdf-generator/js/scripts.js?ver=

HTML / DOM Fingerprints

JS Globals
tsml_programstsml_program
FAQ

Frequently Asked Questions about 12 Step Meeting PDF