
bSuite Security & Risk Analysis
wordpress.org/plugins/bsuiteA suite of tools used to help surface interesting and popular stories as well as improve WordPress' CMS capabilities as an application platform.
Is bSuite Safe to Use in 2026?
Generally Safe
Score 85/100bSuite has a strong security track record. Known vulnerabilities have been patched promptly.
The "bsuite" v5 alpha 3 plugin presents a mixed security posture. While it demonstrates some positive security practices, such as a significant number of capability checks and a lack of bundled libraries, several concerning areas were identified. The static analysis reveals a substantial attack surface, with a notable portion of AJAX handlers (7 out of 11) lacking proper authentication checks. Furthermore, a concerning number of dangerous functions are present in the codebase, including `unserialize`, `shell_exec`, and `create_function`, which can be exploited if not handled with extreme care. The taint analysis, although not revealing critical or high severity flows, indicates a high number of flows with unsanitized paths, suggesting a potential for vulnerabilities if input validation is not robust. Historically, the plugin has a known medium severity CVE for Cross-site Scripting, and while there are no currently unpatched vulnerabilities, the age of the last known vulnerability (2014) suggests potential for outdated or undiscovered security flaws within the current codebase that may not be reflected in past CVEs. Overall, the plugin requires careful review and hardening due to its large, partially unprotected attack surface and the presence of dangerous functions.
Key Concerns
- Unprotected AJAX handlers
- Presence of dangerous functions (unserialize, shell_exec, create_function)
- High number of flows with unsanitized paths
- Low percentage of properly escaped output
- Low number of nonce checks
- SQL queries not always using prepared statements
- Known medium severity vulnerability in history
bSuite Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
bSuite <= 5 alpha 2 - Multiple Cross-Site Scripting
bSuite Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
bSuite Attack Surface
AJAX Handlers 11
Shortcodes 8
WordPress Hooks 124
Scheduled Events 5
Maintenance & Trust
bSuite Maintenance & Trust
Maintenance Signals
Community Trust
bSuite Alternatives
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
burst-statistics
Analytics you'll actually use. Privacy-friendly, zero config, and designed to be actionable. Get insights, not just raw data.
Statify
statify
Visitor statistics for WordPress with focus on data protection, transparency and clarity. Perfect as a widget in your WordPress Dashboard.
StatCounter – Free Real Time Visitor Stats
official-statcounter-plugin-for-wordpress
StatCounter.com powered real-time detailed stats about the visitors to your blog.
Koko Analytics – Privacy Friendly Statistics for WordPress
koko-analytics
Koko Analytics is a privacy-friendly statistics plugin for WordPress that is an easy to use alternative to Google Analytics.
Connect Matomo – Analytics Dashboard for WordPress
wp-piwik
Adds Matomo (former Piwik) statistics to your WordPress dashboard and is also able to add the Matomo Tracking Code to your blog.
bSuite Developer Profile
7 plugins · 290 total installs
How We Detect bSuite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bsuite/js/bsuite.js/wp-content/plugins/bsuite/js/jquery.highlight-1.js/wp-content/plugins/bsuite/js/bsuite.js/wp-content/plugins/bsuite/js/jquery.highlight-1.jsbsuite/js/bsuite.js?ver=bsuite/js/jquery.highlight-1.js?ver=HTML / DOM Fingerprints
bsuitebsuite_mycss_replacethemecss[include[icon[feed