24liveblog – live blog tool Security & Risk Analysis

wordpress.org/plugins/24liveblog

24liveblog is the most popular live blog tool, trusted by thousands of publishers.

700 active installs v2.2 PHP + WP 3.5+ Updated Dec 6, 2023
live-bloglive-blogginglive-commentaryliveblog
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is 24liveblog – live blog tool Safe to Use in 2026?

Generally Safe

Score 85/100

24liveblog – live blog tool has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The 24liveblog plugin v2.2 demonstrates a generally strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is highly commendable. Furthermore, the plugin utilizes prepared statements for its SQL queries and has a very high rate of properly escaped output, indicating good development practices for preventing common vulnerabilities like SQL injection and XSS. The presence of nonce and capability checks on its single AJAX handler adds a layer of defense against unauthorized actions.

While the code analysis shows positive signs, the attack surface, though small and seemingly protected, is an area to always monitor. The vulnerability history is notably clean, with no recorded CVEs. This suggests either a history of secure development or a lack of significant past security focus from attackers, or perhaps a combination of both. The lack of critical or high-severity taint flows further reinforces the idea of a well-written codebase from a security perspective.

Overall, 24liveblog v2.2 appears to be a secure plugin. The strengths lie in its clean code, proper sanitization, and lack of historical vulnerabilities. The only minor area for potential improvement would be to ensure continuous vigilance and potentially broaden the scope of security testing to identify any very subtle or novel attack vectors that might not be caught by standard static analysis. However, based on the data, the risk associated with this plugin is very low.

Vulnerabilities
None known

24liveblog – live blog tool Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

24liveblog – live blog tool Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
29 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped33 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
update_lb24_token (plugin.php:93)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

24liveblog – live blog tool Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_update_lb24_tokenplugin.php:114
WordPress Hooks 6
actionadmin_menuplugin.php:111
actionadmin_noticesplugin.php:112
actionadmin_enqueue_scriptsplugin.php:113
filterblock_categoriessrc\init.php:160
actioninitsrc\init.php:161
actionenqueue_block_editor_assetssrc\init.php:162
Maintenance & Trust

24liveblog – live blog tool Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedDec 6, 2023
PHP min version
Downloads38K

Community Trust

Rating86/100
Number of ratings12
Active installs700
Developer Profile

24liveblog – live blog tool Developer Profile

24liveblog

1 plugin · 700 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect 24liveblog – live blog tool

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/24liveblog/assets/lb24-notice.css/wp-content/plugins/24liveblog/assets/lb24-settings.css/wp-content/plugins/24liveblog/assets/lb24-settings.js
Script Paths
/wp-content/plugins/24liveblog/assets/lb24-settings.js

HTML / DOM Fingerprints

CSS Classes
lb24-notice-wrapper
HTML Comments
<!-- WP Localized globals. Use dynamic PHP stuff in JavaScript via `cgbGlobal` object. -->
Data Attributes
data-getlogingurldata-getwpuserinfodata-getwpuseriddata-getwpusernamedata-getlb24tokendata-getlb24uid+3 more
JS Globals
lb24WpDatacgbGlobal
FAQ

Frequently Asked Questions about 24liveblog – live blog tool