Bread & Butter: AI-Powered Lead Intelligence Security & Risk Analysis

wordpress.org/plugins/bread-butter

Turn anonymous traffic into revenue. Get verified leads from your existing forms - no changes required. Automatically enrich user profiles with real j …

30 active installs v8.6.0.107 PHP 7.0.0+ WP 1.0+ Updated Mar 26, 2026
ai-marketingcontent-gatinglead-capturelead-enrichmentlead-generation
74
B · Generally Safe
CVEs total3
Unpatched1
Last CVEApr 21, 2026
Safety Verdict

Is Bread & Butter: AI-Powered Lead Intelligence Safe to Use in 2026?

Mostly Safe

Score 74/100

Bread & Butter: AI-Powered Lead Intelligence is generally safe to use. 3 past CVEs were resolved.

3 known CVEs 1 unpatched Last CVE: Apr 21, 2026Updated 1mo ago
Risk Assessment

The 'bread-butter' plugin version 8.5.0.100 exhibits a generally good security posture based on the static analysis. The absence of any unprotected entry points, such as AJAX handlers, REST API routes, shortcodes, or cron events, significantly limits the direct attack surface. The plugin also demonstrates good practices in SQL query handling, with 100% of queries using prepared statements, and a high percentage (92%) of output being properly escaped, which mitigates common cross-site scripting vulnerabilities. The presence of nonce and capability checks further strengthens its defenses. However, the static analysis did reveal a concerning number of flows with unsanitized paths (28 out of 32), although thankfully none were classified as critical or high severity. This indicates a potential for vulnerabilities if user input is not rigorously validated before being used in file operations or other sensitive functions.

The vulnerability history of the plugin is a significant concern. With two known medium-severity CVEs, specifically Cross-Site Request Forgery and Cross-site Scripting, it suggests a recurring pattern of insecure coding practices that have previously led to exploitable vulnerabilities. While there are currently no unpatched CVEs, the existence of past vulnerabilities of these types, coupled with the unsanitized path flows in the static analysis, warrants caution. The plugin's strengths lie in its controlled entry points and proper SQL/output handling, but the past vulnerability record and the identified unsanitized path flows are weaknesses that cannot be overlooked, suggesting a need for more comprehensive input sanitization and ongoing security audits.

Key Concerns

  • 2 known medium CVEs
  • 28 flows with unsanitized paths
  • Bundled library (Select2) may be outdated
Vulnerabilities
3 published

Bread & Butter: AI-Powered Lead Intelligence Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2025
2025
1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2026-4279medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Bread & Butter: Content Gating for Verified Leads <= 8.2.0.25 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

Apr 21, 2026Unpatched
CVE-2025-12189medium · 4.3Cross-Site Request Forgery (CSRF)

Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents <= 7.11.1374 - Cross-Site Request Forgery to Arbitrary File Upload

Dec 4, 2025 Patched in 8.0.1398 (5d)
CVE-2024-51802medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Lead capture, gated content & newsletter opt-ins <= 7.4.857 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 8, 2024 Patched in 7.5.880 (29d)
Version History

Bread & Butter: AI-Powered Lead Intelligence Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Bread & Butter: AI-Powered Lead Intelligence Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
62
762 escaped
Nonce Checks
4
Capability Checks
4
File Operations
14
External Requests
2
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared1 total queries

Output Escaping

92% escaped824 total outputs
Data Flows · Security
28 unsanitized

Data Flow Analysis

25 flows28 with unsanitized paths
createAdminUser (src\Base\Ajax.php:257)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Bread & Butter: AI-Powered Lead Intelligence Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 33
actioninitbreadbutter-connect.php:34
actionadmin_menusrc\Api\SettingsApi.php:23
actionadmin_initsrc\Api\SettingsApi.php:27
actioninitsrc\Api\SettingsApi.php:39
actionupdated_optionsrc\Api\SettingsApi.php:42
actionrest_api_initsrc\Api\SettingsApi.php:151
actioninitsrc\Base\Ajax.php:79
actionwp_enqueue_scriptssrc\Base\ContactUs.php:13
filterscript_loader_tagsrc\Base\Enqueue.php:17
actionwp_headsrc\Base\Enqueue.php:18
actionwp_enqueue_scriptssrc\Base\Enqueue.php:19
actionwp_enqueue_scriptssrc\Base\Enqueue.php:20
actionadmin_enqueue_scriptssrc\Base\Enqueue.php:21
actionlogin_enqueue_scriptssrc\Base\Enqueue.php:22
filterwp_nav_menu_objectssrc\Base\Enqueue.php:23
actionafter_setup_themesrc\Base\Enqueue.php:24
actionadmin_initsrc\Base\Enqueue.php:25
actionadmin_noticessrc\Base\Enqueue.php:26
filtershow_admin_barsrc\Base\Enqueue.php:46
actionwp_footersrc\Base\Enqueue.php:69
filterthe_contentsrc\Base\GatingContent.php:16
filterpre_get_postssrc\Base\GatingContent.php:17
actionwp_enqueue_scriptssrc\Base\GatingContent.php:18
actionwp_enqueue_scriptssrc\Base\Newsletter.php:13
actioninitsrc\Base\Session.php:12
actionwp_logoutsrc\Base\Session.php:13
actioninitsrc\Base\Shortcode.php:43
actionadmin_initsrc\Pages\Admin.php:75
actionenqueue_block_editor_assetssrc\Pages\Block.php:29
actionlogin_formsrc\Pages\LoginForm.php:15
actionregister_formsrc\Pages\LoginForm.php:16
actionlogin_formsrc\Pages\LoginForm.php:17
actionregister_formsrc\Pages\LoginForm.php:18
Maintenance & Trust

Bread & Butter: AI-Powered Lead Intelligence Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 26, 2026
PHP min version7.0.0
Downloads6K

Community Trust

Rating94/100
Number of ratings7
Active installs30
Developer Profile

Bread & Butter: AI-Powered Lead Intelligence Developer Profile

Bread & Butter

1 plugin · 30 total installs

76
trust score
Avg Security Score
74/100
Avg Patch Time
17 days
View full developer profile
Detection Fingerprints

How We Detect Bread & Butter: AI-Powered Lead Intelligence

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bread-butter/src/assets/css/breadbutter-contactus.css/wp-content/plugins/bread-butter/src/assets/js/breadbutter-contactus.js
Script Paths
/wp-content/plugins/bread-butter/src/assets/js/breadbutter-contactus.js
Version Parameters
breadbutter-contactus.css?ver=breadbutter-contactus.js?ver=

HTML / DOM Fingerprints

JS Globals
BB_POST_CONTACTUSBB_CONTACTUS_OVERRIDE_REG_DESTINATION_URLBB_POST_CONTACTUS_DATA
FAQ

Frequently Asked Questions about Bread & Butter: AI-Powered Lead Intelligence