
Broadly for WordPress Security & Risk Analysis
wordpress.org/plugins/broadlyBroadly allows your business to easily communicate with your customers. Manage your online reputation and customer communications across SMS and email …
Is Broadly for WordPress Safe to Use in 2026?
Use With Caution
Score 64/100Broadly for WordPress has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "broadly" v3.0.2 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no identifiable attack surface through AJAX handlers, REST API routes, shortcodes, or cron events, and all SQL queries utilize prepared statements, indicating good practices in these areas. The absence of critical or high severity taint flows is also a positive sign.
However, significant concerns arise from the vulnerability history. The presence of one unpatched medium severity CVE, specifically Cross-Site Scripting (XSS), dating from June 2025, is a critical flag. This indicates a known vulnerability that remains exploitable. Furthermore, the static analysis shows that only 50% of output is properly escaped, and there are no nonce or capability checks present. While the attack surface appears small, the lack of proper input validation and output escaping, coupled with an unpatched vulnerability, creates a tangible risk of XSS attacks.
In conclusion, while the plugin demonstrates some secure coding practices, the unpatched XSS vulnerability and the identified issues with output escaping and capability checks present a clear and present danger. The plugin's strengths in SQL handling and attack surface minimization are overshadowed by the exploitable vulnerability and the potential for further injection flaws due to insufficient escaping and authorization checks.
Key Concerns
- Unpatched medium CVE for XSS
- Only 50% of output properly escaped
- Missing nonce checks
- Missing capability checks
Broadly for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Broadly for WordPress <= 3.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Broadly for WordPress Release Timeline
Broadly for WordPress Code Analysis
Output Escaping
Broadly for WordPress Attack Surface
WordPress Hooks 5
Maintenance & Trust
Broadly for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Broadly for WordPress Alternatives
HubSpot All-In-One Marketing – Forms, Popups, Live Chat
leadin
The CRM, Sales, and Marketing WordPress plugin to grow your business better. Capture and engage web visitors with free live chat, forms, CRM, email ma …
FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution
fluent-crm
The easiest and fastest Email Marketing, Newsletter, Marketing Automation Plugin & CRM Solution for WordPress
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation
zero-bs-crm
The CRM for small businesses. Manage leads, invoicing, billing, email marketing, clients, contacts, quotes, automation. Works with WooCommerce too.
LeadConnector
leadconnector
Connect WordPress to LeadConnector for chat widgets, funnels, forms, calendars, reviews, custom values, and CRM tools.
SureContact – Newsletters, Email Marketing, Automation, Revenue Tracking & CRM
surecontact
Send newsletters, set up email automations, manage contacts and track ecommerce revenue in a CRM for WordPress.
Broadly for WordPress Developer Profile
1 plugin · 500 total installs
How We Detect Broadly for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/broadly/broadly.phphttps://chat.broadly.com/javascript/chat.jsHTML / DOM Fingerprints
<!-- Start of Broadly "reviews" content - Broadly for WordPress 3.0.2 --><!-- End of Broadly "reviews" content -->window.broadlyChat