
Bread & Butter: Content Gating for Verified Leads Security & Risk Analysis
wordpress.org/plugins/bread-butterTurn anonymous traffic into revenue. Get verified leads from your existing forms - no changes required. Automatically enrich user profiles with real j …
Is Bread & Butter: Content Gating for Verified Leads Safe to Use in 2026?
Generally Safe
Score 98/100Bread & Butter: Content Gating for Verified Leads has a strong security track record. Known vulnerabilities have been patched promptly.
The 'bread-butter' plugin version 8.5.0.100 exhibits a generally good security posture based on the static analysis. The absence of any unprotected entry points, such as AJAX handlers, REST API routes, shortcodes, or cron events, significantly limits the direct attack surface. The plugin also demonstrates good practices in SQL query handling, with 100% of queries using prepared statements, and a high percentage (92%) of output being properly escaped, which mitigates common cross-site scripting vulnerabilities. The presence of nonce and capability checks further strengthens its defenses. However, the static analysis did reveal a concerning number of flows with unsanitized paths (28 out of 32), although thankfully none were classified as critical or high severity. This indicates a potential for vulnerabilities if user input is not rigorously validated before being used in file operations or other sensitive functions.
The vulnerability history of the plugin is a significant concern. With two known medium-severity CVEs, specifically Cross-Site Request Forgery and Cross-site Scripting, it suggests a recurring pattern of insecure coding practices that have previously led to exploitable vulnerabilities. While there are currently no unpatched CVEs, the existence of past vulnerabilities of these types, coupled with the unsanitized path flows in the static analysis, warrants caution. The plugin's strengths lie in its controlled entry points and proper SQL/output handling, but the past vulnerability record and the identified unsanitized path flows are weaknesses that cannot be overlooked, suggesting a need for more comprehensive input sanitization and ongoing security audits.
Key Concerns
- 2 known medium CVEs
- 28 flows with unsanitized paths
- Bundled library (Select2) may be outdated
Bread & Butter: Content Gating for Verified Leads Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents <= 7.11.1374 - Cross-Site Request Forgery to Arbitrary File Upload
Lead capture, gated content & newsletter opt-ins <= 7.4.857 - Authenticated (Contributor+) Stored Cross-Site Scripting
Bread & Butter: Content Gating for Verified Leads Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Bread & Butter: Content Gating for Verified Leads Attack Surface
WordPress Hooks 33
Maintenance & Trust
Bread & Butter: Content Gating for Verified Leads Maintenance & Trust
Maintenance Signals
Community Trust
Bread & Butter: Content Gating for Verified Leads Alternatives
Happierleads – Identify your B2B website visitors even if they work remotely
happierleads
Identify your B2B website visitors that work remotely Generate 3X more leads than your competition by using your existing web traffic
Lead Generation Form
lead-generation-form
Create lead forms with drag-and-drop builder, capture leads, and export data easily.
WPrequal
wprequal
Easy-to-use lead generation, lead capture, lead manager, and form builders. No advanced setup required; works well and looks great out-of-the-box.
Easy Email Integration by WPPOOL
easy-email-integration
Collect leads & emails for Mailchimp, MailPoet, FluentCRM, Brevo & more. Create stunning opt-in forms with Block Editor & Elementor.
Hostinger Reach – AI-Powered Email Marketing for WordPress
hostinger-reach
Launch and grow your email marketing effortlessly with Hostinger Reach. Collect contacts, sync subscribers, and send emails – all in one, AI powered.
Bread & Butter: Content Gating for Verified Leads Developer Profile
1 plugin · 40 total installs
How We Detect Bread & Butter: Content Gating for Verified Leads
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bread-butter/src/assets/css/breadbutter-contactus.css/wp-content/plugins/bread-butter/src/assets/js/breadbutter-contactus.js/wp-content/plugins/bread-butter/src/assets/js/breadbutter-contactus.jsbreadbutter-contactus.css?ver=breadbutter-contactus.js?ver=HTML / DOM Fingerprints
BB_POST_CONTACTUSBB_CONTACTUS_OVERRIDE_REG_DESTINATION_URLBB_POST_CONTACTUS_DATA