
BMLT WordPress Satellite Security & Risk Analysis
wordpress.org/plugins/bmlt-wordpress-satellite-pluginThis is a "satellite" plugin for the Basic Meeting List Toolbox (BMLT).
Is BMLT WordPress Satellite Safe to Use in 2026?
Mostly Safe
Score 78/100BMLT WordPress Satellite is generally safe to use. 1 past CVE were resolved.
The bmlt-wordpress-satellite-plugin v3.11.6 exhibits a mixed security posture. On the positive side, static analysis reveals a lack of direct attack surface through AJAX handlers, REST API routes, shortcodes, or cron events. The plugin also demonstrates good practices regarding SQL queries, exclusively using prepared statements, and the presence of a nonce check. Furthermore, the taint analysis indicates no critical or high severity unsanitized flows, suggesting that user-supplied data is generally handled safely.
However, the plugin has a significant concern: a known, currently unpatched medium severity CVE. The historical vulnerability pattern, with a recent medium severity CSRF vulnerability, indicates a recurring issue that warrants attention. The fact that it remains unpatched is the most critical indicator of risk for this version. While the code appears to have good internal security practices like prepared statements and nonce checks, the existence of an unpatched CVE significantly elevates the overall risk profile.
In conclusion, while the plugin has strengths in its internal code security and limited attack surface, the presence of an unpatched medium severity CVE is a critical weakness. Users of this version are exposed to potential exploitation of this known vulnerability. Therefore, immediate attention should be paid to addressing this outstanding security issue.
Key Concerns
- Unpatched Medium Severity CVE
- Output escaping below 100%
BMLT WordPress Satellite Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
BMLT WordPress Plugin <= 3.11.4 - Cross-Site Request Forgery to Settings Creation and Deletion
BMLT WordPress Satellite Release Timeline
BMLT WordPress Satellite Code Analysis
Output Escaping
Data Flow Analysis
BMLT WordPress Satellite Attack Surface
WordPress Hooks 10
Maintenance & Trust
BMLT WordPress Satellite Maintenance & Trust
Maintenance Signals
Community Trust
BMLT WordPress Satellite Alternatives
BMLT Tabbed Map
bmlt-tabbed-map
bmlt_tabbed_map implements a Tabbed Map for BMLT.
crouton
crouton
crouton provides a UI and more for view recovery meetings as stored in a Basic Meeting List Toolbox (BMLT) database.
Bread
bread
A web-based tool that creates, maintains and generates a PDF meeting list from BMLT.
List Locations BMLT
list-locations-bmlt
List Locations BMLT is a plugin that returns all unique towns or counties from your BMLT server for a given service body on your site.
Upcoming Meetings BMLT
upcoming-meetings-bmlt
Upcoming Meetings BMLT is a plugin that displays the next 'N' number of meetings from the current time on your page or in a widget using the …
BMLT WordPress Satellite Developer Profile
3 plugins · 230 total installs
How We Detect BMLT WordPress Satellite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bmlt-wordpress-satellite-plugin/vendor/bmlt/bmlt-satellite-base-class/table_display.js/wp-content/plugins/bmlt-wordpress-satellite-plugin/admin_styles.css/wp-content/plugins/bmlt-wordpress-satellite-plugin/admin_javascript.jshttps://maps.google.com/maps/api/js?key=bmlt-wordpress-satellite-plugin/bmlt-wordpress-satellite-plugin.phpbmlt-wordpress-satellite-plugin/table_display.jsbmlt-wordpress-satellite-plugin/admin_styles.cssbmlt-wordpress-satellite-plugin/admin_javascript.jsHTML / DOM Fingerprints
<!-- BMLTPlugin ERROR (cms_get_post_meta)! No get_post_meta()! -->window.google