
Bloom for Publishers Security & Risk Analysis
wordpress.org/plugins/bloom-for-publishersGeotag your posts to enable local search and other hyperlocal experiences for your readers.
Is Bloom for Publishers Safe to Use in 2026?
Generally Safe
Score 100/100Bloom for Publishers has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'bloom-for-publishers' v1.7.10 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, 100% proper output escaping, and the exclusive use of prepared statements for SQL queries are significant strengths. The plugin also demonstrates good practice by employing nonce checks, although capability checks are notably absent. The limited attack surface, with only one shortcode and no unprotected entry points, further contributes to its secure design. The vulnerability history is also clean, with no recorded CVEs, suggesting a history of robust security maintenance.
While the static analysis reveals no immediate critical vulnerabilities, the lack of capability checks on the shortcode represents a potential area for concern. If the shortcode's functionality relies on user permissions, its absence could lead to unauthorized access or actions by users who should not have such privileges. However, given the overall excellent security metrics and the lack of any historical vulnerabilities or critical taint flows, the immediate risk appears low. The plugin is well-developed from a security perspective, but a deeper review of the shortcode's implementation is recommended to ensure it properly handles authorization.
Key Concerns
- Missing capability checks on shortcode
Bloom for Publishers Security Vulnerabilities
Bloom for Publishers Release Timeline
Bloom for Publishers Code Analysis
SQL Query Safety
Output Escaping
Bloom for Publishers Attack Surface
Shortcodes 1
WordPress Hooks 22
Maintenance & Trust
Bloom for Publishers Maintenance & Trust
Maintenance Signals
Community Trust
Bloom for Publishers Alternatives
Multiple Domain Mapping on Single Site
multiple-domain-mapping-on-single-site
Show content of specific posts, pages, ... within their own, additional domains. Useful for SEO: different domains for landingpages.
ACF: Image Hotspots Field
acf-image-mapping-hotspots
Advanced Custom Fields add-on to allow the capturing of coordinates on an image, based on user clicks.
Quiz Builder for WooCommerce – Product Recommendations
product-recommendation-quiz-for-ecommerce
Turn WooCommerce shoppers into leads and buyers with an interactive product recommendation quiz builder.
Sailthru for WordPress
sailthru-widget
Provides an integration with Sailthru
Geo Controller
cf-geoplugin
Enhance your WordPress site with Geo Controller – a comprehensive plugin offering advanced location-based features and personalized content delivery.
Bloom for Publishers Developer Profile
1 plugin · 90 total installs
How We Detect Bloom for Publishers
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bloom-for-publishers/css/admin-post.css/wp-content/plugins/bloom-for-publishers/css/global.css/wp-content/plugins/bloom-for-publishers/js/admin-post.js/wp-content/plugins/bloom-for-publishers/js/geocode.jshttps://maps.googleapis.com/maps/api/js?language=en&key=bloom-for-publishers/css/admin-post.css?ver=bloom-for-publishers/css/global.css?ver=bloom-for-publishers/js/admin-post.js?ver=bloom-for-publishers/js/geocode.js?ver=HTML / DOM Fingerprints
blm_location_formAdmin Post: admin-post.phpNote: In block editor (Gutenberg), this doesn't show by defaultNote cont. A redundant message is displayed in the Post Location sectiondata-code