BMLT WordPress Satellite Security & Risk Analysis

wordpress.org/plugins/bmlt-wordpress-satellite-plugin

This is a "satellite" plugin for the Basic Meeting List Toolbox (BMLT).

100 active installs v3.11.6 PHP 8.1+ WP 6.2+ Updated Mar 20, 2026
bmltmeeting-findermeeting-listnarecovery
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEDec 11, 2025
Safety Verdict

Is BMLT WordPress Satellite Safe to Use in 2026?

Mostly Safe

Score 78/100

BMLT WordPress Satellite is generally safe to use. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Dec 11, 2025Updated 1mo ago
Risk Assessment

The bmlt-wordpress-satellite-plugin v3.11.6 exhibits a mixed security posture. On the positive side, static analysis reveals a lack of direct attack surface through AJAX handlers, REST API routes, shortcodes, or cron events. The plugin also demonstrates good practices regarding SQL queries, exclusively using prepared statements, and the presence of a nonce check. Furthermore, the taint analysis indicates no critical or high severity unsanitized flows, suggesting that user-supplied data is generally handled safely.

However, the plugin has a significant concern: a known, currently unpatched medium severity CVE. The historical vulnerability pattern, with a recent medium severity CSRF vulnerability, indicates a recurring issue that warrants attention. The fact that it remains unpatched is the most critical indicator of risk for this version. While the code appears to have good internal security practices like prepared statements and nonce checks, the existence of an unpatched CVE significantly elevates the overall risk profile.

In conclusion, while the plugin has strengths in its internal code security and limited attack surface, the presence of an unpatched medium severity CVE is a critical weakness. Users of this version are exposed to potential exploitation of this known vulnerability. Therefore, immediate attention should be paid to addressing this outstanding security issue.

Key Concerns

  • Unpatched Medium Severity CVE
  • Output escaping below 100%
Vulnerabilities
1 published

BMLT WordPress Satellite Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-14162medium · 4.3Cross-Site Request Forgery (CSRF)

BMLT WordPress Plugin <= 3.11.4 - Cross-Site Request Forgery to Settings Creation and Deletion

Dec 11, 2025Unpatched
Version History

BMLT WordPress Satellite Release Timeline

v3.11.6Current1 CVE
v3.11.41 CVE
v3.11.31 CVE
v3.11.21 CVE
v3.11.11 CVE
v3.11.01 CVE
v3.10.01 CVE
v3.9.01 CVE
Code Analysis
Analyzed Apr 16, 2026

BMLT WordPress Satellite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
9 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped12 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<bmlt-wordpress-satellite-plugin> (bmlt-wordpress-satellite-plugin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

BMLT WordPress Satellite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionwp_enqueue_scriptsbmlt-wordpress-satellite-plugin.php:77
filterthe_contentbmlt-wordpress-satellite-plugin.php:646
filterwp_headbmlt-wordpress-satellite-plugin.php:647
filteradmin_headbmlt-wordpress-satellite-plugin.php:648
filterplugin_action_linksbmlt-wordpress-satellite-plugin.php:649
actionpre_get_postsbmlt-wordpress-satellite-plugin.php:655
actionadmin_initbmlt-wordpress-satellite-plugin.php:656
actionadmin_menubmlt-wordpress-satellite-plugin.php:657
actionadmin_enqueue_scriptsbmlt-wordpress-satellite-plugin.php:658
actioninitbmlt-wordpress-satellite-plugin.php:659
Maintenance & Trust

BMLT WordPress Satellite Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 20, 2026
PHP min version8.1
Downloads13K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

BMLT WordPress Satellite Developer Profile

BMLTGuy

3 plugins · 230 total installs

91
trust score
Avg Security Score
87/100
Avg Patch Time
4 days
View full developer profile
Detection Fingerprints

How We Detect BMLT WordPress Satellite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bmlt-wordpress-satellite-plugin/vendor/bmlt/bmlt-satellite-base-class/table_display.js/wp-content/plugins/bmlt-wordpress-satellite-plugin/admin_styles.css/wp-content/plugins/bmlt-wordpress-satellite-plugin/admin_javascript.js
Script Paths
https://maps.google.com/maps/api/js?key=
Version Parameters
bmlt-wordpress-satellite-plugin/bmlt-wordpress-satellite-plugin.phpbmlt-wordpress-satellite-plugin/table_display.jsbmlt-wordpress-satellite-plugin/admin_styles.cssbmlt-wordpress-satellite-plugin/admin_javascript.js

HTML / DOM Fingerprints

HTML Comments
<!-- BMLTPlugin ERROR (cms_get_post_meta)! No get_post_meta()! -->
JS Globals
window.google
FAQ

Frequently Asked Questions about BMLT WordPress Satellite