Bg Church Memos Security & Risk Analysis

wordpress.org/plugins/bg-church-memos

Orhodox church memos on your site.

30 active installs v1.1 PHP + WP 3.0.1+ Updated Jan 2, 2017
christianity%d0%bf%d1%80%d0%b0%d0%b2%d0%be%d1%81%d0%bb%d0%b0%d0%b2%d0%b8%d0%b5%ce%bf%cf%81%ce%b8%ce%bf%ce%b4%ce%bf%ce%be%ce%af%ce%b1%d1%85%d1%80%d0%b8%d1%81%d1%82%d0%b8%d0%b0%d0%bd%d1%81%d1%82%d0%b2%d0%beorthodoxy
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 22, 2025
Safety Verdict

Is Bg Church Memos Safe to Use in 2026?

Use With Caution

Score 63/100

Bg Church Memos has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 22, 2025Updated 9yr ago
Risk Assessment

The "bg-church-memos" plugin v1.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by having no detected dangerous functions, all SQL queries utilizing prepared statements, and no file operations or external HTTP requests. Furthermore, the attack surface is minimal, with only one shortcode and no AJAX handlers or REST API routes to consider. However, significant concerns arise from the lack of output escaping and the absence of nonce and capability checks. The fact that 0% of outputs are properly escaped is a critical vulnerability, as it leaves the plugin highly susceptible to Cross-Site Scripting (XSS) attacks.

The vulnerability history for this plugin is a major red flag. With one known CVE, and critically, one currently unpatched medium severity vulnerability related to XSS, the plugin's maintainers have demonstrated a failure to address known security flaws promptly. The last vulnerability being so recent (2025-09-22) suggests ongoing issues or a lack of proactive security maintenance. While the static analysis shows no *new* critical taint flows or unsanitized paths, the existing unpatched vulnerability, combined with the lack of output escaping, creates a high-risk environment.

In conclusion, while the plugin avoids certain common pitfalls like raw SQL and dangerous functions, the critical flaw of unescaped output and the existence of an unpatched XSS vulnerability severely undermine its security. The lack of comprehensive capability and nonce checks on its single entry point (shortcode) further exacerbates the risk. Users should consider this plugin a high risk due to the unpatched vulnerability and inherent XSS potential, until these issues are addressed.

Key Concerns

  • Unpatched Medium CVE
  • 0% Output Escaping
  • 0 Capability Checks
  • 0 Nonce Checks
Vulnerabilities
1 published

Bg Church Memos Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-58242medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Bg Church Memos <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 22, 2025Unpatched
Version History

Bg Church Memos Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Bg Church Memos Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Bg Church Memos Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[memos_button] bg_church-memos.php:61
WordPress Hooks 1
actionwp_headbg_church-memos.php:52
Maintenance & Trust

Bg Church Memos Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.0
Last updatedJan 2, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Bg Church Memos Developer Profile

Vadim Bogaiskov

7 plugins · 1K total installs

81
trust score
Avg Security Score
82/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bg Church Memos

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bg-church-memos/notes.html

HTML / DOM Fingerprints

CSS Classes
memos_button
HTML Comments
Блок загрузки плагинаЗапрет прямого запуска скриптаФункции запуска плагинаРегистрируем шорт-код memos+1 more
Data Attributes
onClick='memos_button()'
JS Globals
memos_button
Shortcode Output
<button class='memos_button' onClick='memos_button();'>Записки в храм</button>
FAQ

Frequently Asked Questions about Bg Church Memos