
Broadcast to Telegram Security & Risk Analysis
wordpress.org/plugins/broadcast-to-telegramAllows WordPress sites to send notifications to a Telegram channel. It's possible send notification to multiple channels.
Is Broadcast to Telegram Safe to Use in 2026?
Generally Safe
Score 85/100Broadcast to Telegram has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The broadcast-to-telegram plugin v1.2.0 exhibits a mixed security posture. While it impressively reports zero AJAX handlers, REST API routes, shortcodes, or cron events, indicating a minimal direct attack surface, this is overshadowed by significant concerns within its code analysis. The absence of capability checks is particularly alarming, suggesting that all functionalities could potentially be accessed by any user. Furthermore, the critical finding of 100% of SQL queries being unescaped, coupled with 100% of output not being properly escaped, points to a high risk of SQL injection and Cross-Site Scripting (XSS) vulnerabilities. The taint analysis revealing unsanitized paths, while not reaching critical or high severity in this report, is a red flag that warrants attention.
Its vulnerability history is clean, with no recorded CVEs, which is a positive sign. This suggests a history of responsible development or limited exposure. However, the absence of past vulnerabilities does not negate the risks identified in the current static analysis. The plugin demonstrates a strength in not using bundled libraries and performing external HTTP requests securely (implied by absence of specific concerns). The presence of one nonce check is a positive, though its effectiveness is undermined by the lack of capability checks. The overall risk is moderate to high due to the easily exploitable code-level weaknesses, despite the lack of a public vulnerability record.
Key Concerns
- 100% SQL queries not using prepared statements
- 100% output not properly escaped
- 0 Capability checks present
- 2 Flows with unsanitized paths
Broadcast to Telegram Security Vulnerabilities
Broadcast to Telegram Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Broadcast to Telegram Attack Surface
WordPress Hooks 3
Maintenance & Trust
Broadcast to Telegram Maintenance & Trust
Maintenance Signals
Community Trust
Broadcast to Telegram Alternatives
WP Telegram (Auto Post and Notifications)
wptelegram
Integrate your WordPress site perfectly with Telegram with full control.
Joinchat
creame-whatsapp-me
WhatsApp, Messenger, Telegram, Phone call… capture users through their favorite Apps and turn into clients
Notification for Telegram
notification-for-telegram
Sends notifications to Telegram users or groups, when some events occur in WordPress.
WP Telegram Widget and Join Link
wptelegram-widget
Display the Telegram Public Channel or Group Feed in a WordPress widget or anywhere you want using a simple shortcode.
All-in-one Chat Button by anychat.one
anychat-widget
Free wordpress widget for live chat via WhatsApp, Facebook Messenger, Telegram and other chat apps.
Broadcast to Telegram Developer Profile
1 plugin · 10 total installs
How We Detect Broadcast to Telegram
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/broadcast-to-telegram/images/telegram-icon.pngHTML / DOM Fingerprints
<!-- Notify to Telegram -->name="brtg_wasSent"id="brtg_wasSent"name="brtg_channels[]"id="