Broadly for WordPress Security & Risk Analysis

wordpress.org/plugins/broadly

Broadly allows your business to easily communicate with your customers. Manage your online reputation and customer communications across SMS and email …

500 active installs v3.0.2 PHP + WP 3.0.2+ Updated Nov 29, 2019
broadlycrmmarketingreviewssmb
64
C · Use Caution
CVEs total1
Unpatched1
Last CVEJun 5, 2025
Download
Safety Verdict

Is Broadly for WordPress Safe to Use in 2026?

Use With Caution

Score 64/100

Broadly for WordPress has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Jun 5, 2025Updated 6yr ago
Risk Assessment

The "broadly" v3.0.2 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no identifiable attack surface through AJAX handlers, REST API routes, shortcodes, or cron events, and all SQL queries utilize prepared statements, indicating good practices in these areas. The absence of critical or high severity taint flows is also a positive sign.

However, significant concerns arise from the vulnerability history. The presence of one unpatched medium severity CVE, specifically Cross-Site Scripting (XSS), dating from June 2025, is a critical flag. This indicates a known vulnerability that remains exploitable. Furthermore, the static analysis shows that only 50% of output is properly escaped, and there are no nonce or capability checks present. While the attack surface appears small, the lack of proper input validation and output escaping, coupled with an unpatched vulnerability, creates a tangible risk of XSS attacks.

In conclusion, while the plugin demonstrates some secure coding practices, the unpatched XSS vulnerability and the identified issues with output escaping and capability checks present a clear and present danger. The plugin's strengths in SQL handling and attack surface minimization are overshadowed by the exploitable vulnerability and the potential for further injection flaws due to insufficient escaping and authorization checks.

Key Concerns

  • Unpatched medium CVE for XSS
  • Only 50% of output properly escaped
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
1 published

Broadly for WordPress Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-30938medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Broadly for WordPress <= 3.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

Jun 5, 2025Unpatched
Version History

Broadly for WordPress Release Timeline

v3.0.2Current1 CVE
v3.0.11 CVE
v3.0.01 CVE
v2.0.31 CVE
v2.0.21 CVE
v2.0.11 CVE
v2.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Broadly for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

50% escaped6 total outputs
Attack Surface

Broadly for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menubroadly.php:29
actionadmin_initbroadly.php:32
filterthe_contentbroadly.php:35
actionwp_headbroadly.php:38
filterhttp_request_argsbroadly.php:97
Maintenance & Trust

Broadly for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedNov 29, 2019
PHP min version
Downloads21K

Community Trust

Rating100/100
Number of ratings3
Active installs500
Developer Profile

Broadly for WordPress Developer Profile

broadly

1 plugin · 500 total installs

69
trust score
Avg Security Score
64/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Broadly for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/broadly/broadly.php
Script Paths
https://chat.broadly.com/javascript/chat.js

HTML / DOM Fingerprints

HTML Comments
<!-- Start of Broadly "reviews" content - Broadly for WordPress 3.0.2 --><!-- End of Broadly "reviews" content -->
JS Globals
window.broadlyChat
FAQ

Frequently Asked Questions about Broadly for WordPress