
Bg Church Memos Security & Risk Analysis
wordpress.org/plugins/bg-church-memosOrhodox church memos on your site.
Is Bg Church Memos Safe to Use in 2026?
Use With Caution
Score 63/100Bg Church Memos has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "bg-church-memos" plugin v1.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by having no detected dangerous functions, all SQL queries utilizing prepared statements, and no file operations or external HTTP requests. Furthermore, the attack surface is minimal, with only one shortcode and no AJAX handlers or REST API routes to consider. However, significant concerns arise from the lack of output escaping and the absence of nonce and capability checks. The fact that 0% of outputs are properly escaped is a critical vulnerability, as it leaves the plugin highly susceptible to Cross-Site Scripting (XSS) attacks.
The vulnerability history for this plugin is a major red flag. With one known CVE, and critically, one currently unpatched medium severity vulnerability related to XSS, the plugin's maintainers have demonstrated a failure to address known security flaws promptly. The last vulnerability being so recent (2025-09-22) suggests ongoing issues or a lack of proactive security maintenance. While the static analysis shows no *new* critical taint flows or unsanitized paths, the existing unpatched vulnerability, combined with the lack of output escaping, creates a high-risk environment.
In conclusion, while the plugin avoids certain common pitfalls like raw SQL and dangerous functions, the critical flaw of unescaped output and the existence of an unpatched XSS vulnerability severely undermine its security. The lack of comprehensive capability and nonce checks on its single entry point (shortcode) further exacerbates the risk. Users should consider this plugin a high risk due to the unpatched vulnerability and inherent XSS potential, until these issues are addressed.
Key Concerns
- Unpatched Medium CVE
- 0% Output Escaping
- 0 Capability Checks
- 0 Nonce Checks
Bg Church Memos Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Bg Church Memos <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Bg Church Memos Release Timeline
Bg Church Memos Code Analysis
Output Escaping
Bg Church Memos Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Bg Church Memos Maintenance & Trust
Maintenance Signals
Community Trust
Bg Church Memos Alternatives
Daily Bible Verse
daily-bible-verse
This plugin lets you add a Bible Verse of the Day widget to your WordPress page.
Bible Daily Reading Plan
esolleso-daily-bible-reading-plan
A comprehensive one-year Bible reading plan plugin for WordPress that helps users read through the entire Bible systematically.
GodInterest Share Button
godinterest-share-button
Add a "Share to Godinterest" Button to your site and get your visitors to start sharing your awesome content!.
PrimeBible Verse Preview
primebible
Automatically detects Bible references and displays beautiful verse previews on hover or tap. Mobile-optimized, fast, and fully customizable.
Bg Church Memos Developer Profile
7 plugins · 1K total installs
How We Detect Bg Church Memos
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bg-church-memos/notes.htmlHTML / DOM Fingerprints
memos_buttonБлок загрузки плагинаЗапрет прямого запуска скриптаФункции запуска плагинаРегистрируем шорт-код memos+1 moreonClick='memos_button()'memos_button<button class='memos_button' onClick='memos_button();'>Записки в храм</button>