Blog Coach Security & Risk Analysis

wordpress.org/plugins/blog-coach

Get Blogging! Amp up your blogging with visual reminders in the admin toolbar to publish a new post.

10 active installs v1.0.0 PHP + WP 3.0.1+ Updated Feb 8, 2016
blogging-coachcoachwriting
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Blog Coach Safe to Use in 2026?

Generally Safe

Score 85/100

Blog Coach has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'blog-coach' v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and avoids known dangerous functions and bundled libraries. The absence of recorded vulnerabilities, including CVEs, is also a strong indicator of a historically secure plugin. However, significant concerns arise from the static analysis, particularly the presence of an unprotected AJAX handler. This single unprotected entry point represents a substantial attack surface and a critical oversight in securing plugin functionality. While the plugin performs capability checks, the lack of nonce checks on the AJAX handler leaves it vulnerable to CSRF attacks.

Key Concerns

  • AJAX handler without authentication
  • Half of output escapes are not proper
  • No nonce checks on AJAX handlers
Vulnerabilities
None known

Blog Coach Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Blog Coach Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Blog Coach Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
2 escaped
Nonce Checks
0
Capability Checks
2
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

50% escaped4 total outputs
Attack Surface
1 unprotected

Blog Coach Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_bgc_mailing_listblog-coach.php:415
WordPress Hooks 9
actionadmin_menublog-coach.php:9
actionadmin_bar_menublog-coach.php:111
actionadd_meta_boxesblog-coach.php:148
actionpublish_postblog-coach.php:157
actionedit_form_topblog-coach.php:161
actionadmin_headblog-coach.php:200
actionwp_dashboard_setupblog-coach.php:342
actionadmin_enqueue_scriptsblog-coach.php:344
filterbgc_admin_pointersblog-coach.php:388
Maintenance & Trust

Blog Coach Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedFeb 8, 2016
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Blog Coach Developer Profile

Scott Winterroth

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Blog Coach

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
bgc_form_checkboxbgc-greenbgc-yellowbgc-orangebgc-red
Data Attributes
id="bgc_container"id="bgc_header"class="bgc_header_area"id="bgc_visual_reminder"id="bgc_visual_feedback"id="bgc-sortables"+1 more
JS Globals
window.onload
FAQ

Frequently Asked Questions about Blog Coach