
bCMS Security & Risk Analysis
wordpress.org/plugins/bcmsA suite of tools that improve WordPress' CMS capabilities.
Is bCMS Safe to Use in 2026?
Generally Safe
Score 85/100bCMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bcms" plugin version 5.3 exhibits a mixed security posture. While the static analysis indicates a relatively small attack surface with all identified entry points seemingly protected by authentication checks (no unprotected AJAX handlers or REST API routes), there are several concerning code signals. The presence of a "unserialize" function without explicit warnings about its use is a significant red flag, as it can lead to serious vulnerabilities if used with untrusted input. Furthermore, a substantial portion of SQL queries are not using prepared statements, increasing the risk of SQL injection. The low percentage of properly escaped output also poses a risk for cross-site scripting (XSS) vulnerabilities.
The plugin's vulnerability history is clean, with no known CVEs. This is a positive indicator, suggesting that the developers have either been diligent in securing the code or that the plugin has not been a significant target. However, the lack of historical vulnerabilities does not negate the risks identified in the static analysis. The strengths lie in the seemingly protected entry points and the absence of known exploits. The weaknesses are primarily in the insecure coding practices identified: the use of unserialize, raw SQL queries, and insufficient output escaping.
Key Concerns
- Use of unserialize function
- High percentage of SQL queries not prepared
- Low percentage of properly escaped output
- No nonce checks on entry points
bCMS Security Vulnerabilities
bCMS Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
bCMS Attack Surface
AJAX Handlers 2
Shortcodes 5
WordPress Hooks 50
Maintenance & Trust
bCMS Maintenance & Trust
Maintenance Signals
Community Trust
bCMS Alternatives
Restrict Widgets
restrict-widgets
All in one widgets and sidebars management in WordPress. Allows you to hide or display widgets on specified pages and restrict access for users.
Pagely MultiEdit
pagely-multiedit
MultiEdit adds tinyMCE editable "blocks" to WordPress custom page templates.
Shortcode Generator
shortcode-generator
Generate as many shortcodes. Keep pages synchronized for split testing, or reuse a specific peice of code on multiple pages.
Navigation Du Lapin Blanc
navigation-du-lapin-blanc
This plugin provides integrated navigation for your website. Use WordPress as a CMS for your website and think in navigation terms (main, sub etc.)
bSuite
bsuite
A suite of tools used to help surface interesting and popular stories as well as improve WordPress' CMS capabilities as an application platform.
bCMS Developer Profile
7 plugins · 290 total installs
How We Detect bCMS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bcms/components/js/edit_widgets.js/wp-content/plugins/bcms/components/js/scrollable.min.js/wp-content/plugins/bcms/components/css/scrollable.css/wp-content/plugins/bcms/components/js/edit_widgets.js/wp-content/plugins/bcms/components/js/scrollable.min.jsbcms/components/js/edit_widgets.js?ver=2HTML / DOM Fingerprints
scrollablepostloops_widgeteditor