Bread Security & Risk Analysis

wordpress.org/plugins/bread

A web-based tool that creates, maintains and generates a PDF meeting list from BMLT.

300 active installs v2.9.11 PHP 8.1+ WP 6.2+ Updated Feb 5, 2026
bmltmeeting-listnanarcotics-anonymous
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bread Safe to Use in 2026?

Generally Safe

Score 100/100

Bread has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'bread' plugin v2.9.11 demonstrates a strong security posture based on the provided static analysis. It exhibits excellent practices by having zero unprotected entry points (AJAX, REST API, shortcodes, cron events), indicating a well-defined and secured attack surface. Furthermore, the code successfully avoids dangerous functions, uses prepared statements exclusively for its SQL queries, and properly escapes all output, significantly mitigating common web application vulnerabilities. The presence of nonce and capability checks further reinforces its secure development approach. The vulnerability history is equally impressive, with no known CVEs, which suggests a history of secure coding and diligent maintenance.

While the static analysis reveals no immediate critical or high-severity issues, the presence of file operations (4) and external HTTP requests (2) warrants a cautious approach. Although not flagged as unsanitized in the taint analysis, these operations represent potential vectors for exploitation if not implemented with rigorous input validation and sanitization. The bundled libraries (Select2, TinyMCE, TCPDF) also present a potential, albeit minor, risk if they are outdated and have known vulnerabilities, though this is not indicated in the provided data. Overall, the plugin appears to be very secure with a strong emphasis on defensive coding. The lack of reported vulnerabilities and the robust static analysis results are significant strengths.

Vulnerabilities
None known

Bread Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Bread Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
295 escaped
Nonce Checks
6
Capability Checks
5
File Operations
4
External Requests
2
Bundled Libraries
3

Bundled Libraries

Select2TinyMCETCPDF

Output Escaping

100% escaped296 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
pwsix_process_wizard (admin\class-bread-admin.php:496)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Bread Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
actionplugins_loadedincludes\class-bread.php:479
actionadmin_enqueue_scriptsincludes\class-bread.php:493
actionadmin_enqueue_scriptsincludes\class-bread.php:494
actionadmin_menuincludes\class-bread.php:496
actionBmltEnabled_Submenuincludes\class-bread.php:497
filtertiny_mce_before_initincludes\class-bread.php:498
filtermce_external_pluginsincludes\class-bread.php:499
filtermce_buttonsincludes\class-bread.php:500
actionadmin_initincludes\class-bread.php:502
actionwp_default_editorincludes\class-bread.php:503
filtertiny_mce_versionincludes\class-bread.php:504
actionplugins_loadedincludes\class-bread.php:508
actionadmin_initincludes\class-bread.php:510
actionadmin_initincludes\class-bread.php:511
actionadmin_initincludes\class-bread.php:512
actionplugins_loadedincludes\class-bread.php:514
actionwp_enqueue_scriptsincludes\class-bread.php:529
actionwp_enqueue_scriptsincludes\class-bread.php:530
actionplugins_loadedincludes\class-bread.php:531
Maintenance & Trust

Bread Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 5, 2026
PHP min version8.1
Downloads17K

Community Trust

Rating0/100
Number of ratings0
Active installs300
Developer Profile

Bread Developer Profile

radius314

3 plugins · 600 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bread

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bread/css/jquery-ui.min.css/wp-content/plugins/bread/css/spectrum.min.css/wp-content/plugins/bread/css/tooltipster.bundle.min.css/wp-content/plugins/bread/css/tooltipster-sideTip-noir.min.css/wp-content/plugins/bread/css/admin.css/wp-content/plugins/bread/css/admin-fonts.css/wp-content/plugins/bread/css/select2.min.css/wp-content/plugins/bread/css/smart_wizard_dots.css+8 more
Script Paths
/wp-content/plugins/bread/js/bmlt_meeting_list.js/wp-content/plugins/bread/js/tooltipster.bundle.min.js/wp-content/plugins/bread/js/spectrum.min.js/wp-content/plugins/bread/js/select2.min.js/wp-content/plugins/bread/js/fetch-jsonp.js/wp-content/plugins/bread/js/jquery.smartWizard.js+1 more
Version Parameters
ver=2.9.11

HTML / DOM Fingerprints

CSS Classes
bread-meeting-list-containerbread-meeting-list-itembread-meeting-list-titlebread-meeting-list-timebread-meeting-list-day
HTML Comments
<!-- Generated by Bread plugin -->
Data Attributes
data-bread-meeting-list-iddata-bread-meeting-list-template
JS Globals
meetingDataTemplatesbreadLayoutsbreadTranslationsBreadAdminBreadMeetingList
REST Endpoints
/wp-json/bread/v1/meeting-list
Shortcode Output
[bread_meeting_list[bread_meeting_search
FAQ

Frequently Asked Questions about Bread