
Cloudbridge Mattermost Security & Risk Analysis
wordpress.org/plugins/cloudbridge-mattermostMattermost integration for WordPress. Tested with Mattermost 5.30.1+ and WordPress 5.5+.
Is Cloudbridge Mattermost Safe to Use in 2026?
Generally Safe
Score 100/100Cloudbridge Mattermost has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The cloudbridge-mattermost plugin v2.2.3 exhibits a strong security posture with no recorded vulnerabilities and a seemingly small attack surface. The static analysis reveals a complete absence of AJAX handlers, REST API routes, shortcodes, and cron events that could be exploited. Furthermore, the absence of critical or high-severity taint flows suggests that data is being handled securely in most pathways.
However, there are areas for improvement. The presence of a single SQL query that does not utilize prepared statements is a significant concern. While the plugin has a low percentage of properly escaped outputs (34%), this still presents a potential risk for cross-site scripting (XSS) vulnerabilities if the unescaped outputs are rendered in a context that is susceptible to injection.
The lack of vulnerability history is a positive indicator, suggesting responsible development and patching practices. The use of Guzzle, a common HTTP client library, is noted. Overall, the plugin appears to have a good foundation, but the identified SQL and output escaping issues warrant attention to further harden its security.
Key Concerns
- SQL query not using prepared statements
- Low percentage of properly escaped outputs
Cloudbridge Mattermost Security Vulnerabilities
Cloudbridge Mattermost Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Cloudbridge Mattermost Attack Surface
WordPress Hooks 25
Maintenance & Trust
Cloudbridge Mattermost Maintenance & Trust
Maintenance Signals
Community Trust
Cloudbridge Mattermost Alternatives
Login Security Captcha
login-security-recaptcha
Secure WordPress login, registration, and comment form with Google reCAPTCHA or Cloudflare Turnstile. Prevent Brute-force attacks and more.
DoLogin Security
dologin
Easy Login. 2FA login. Passwordless login. Cloudflare Turnstile reCAPTCHA. GeoLocation (Continent/Country/City)/IP range to limit login attempts.
App for Cloudflare®
app-for-cf
All things Cloudflare (caching, flexible SSL, Turnstile, settings, rules, analytics, media in R2, image transforms [AVIF, WebP], secure admin area).
CloudGuard
cloudguard
Use Cloudflare's free geolocation service to restrict access to your site's login page.
File Manager for Dropbox
integrate-dropbox
Secure Dropbox integration for WordPress. Manage, share, and embed files via blocks, shortcodes, and Elementor widgets.
Cloudbridge Mattermost Developer Profile
5 plugins · 190 total installs
How We Detect Cloudbridge Mattermost
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cloudbridge-mattermost/css/cbmm-admin.css/wp-content/plugins/cloudbridge-mattermost/css/cbmm-frontend.css/wp-content/plugins/cloudbridge-mattermost/js/cbmm-admin.js/wp-content/plugins/cloudbridge-mattermost/js/cbmm-frontend.js/wp-content/plugins/cloudbridge-mattermost/js/cbmm-admin.js/wp-content/plugins/cloudbridge-mattermost/js/cbmm-frontend.jscloudbridge-mattermost/css/cbmm-admin.css?ver=cloudbridge-mattermost/css/cbmm-frontend.css?ver=cloudbridge-mattermost/js/cbmm-admin.js?ver=cloudbridge-mattermost/js/cbmm-frontend.js?ver=HTML / DOM Fingerprints
cbmm-settings-tabcbmm-admin-pageThis file is part of Cloudbridge Mattermost. Cloudbridge Mattermost is free software.Copyright 2020-2026 Joaquim Homrighausen; all rights reserved.data-cbmm-form-iddata-cbmm-is-admin-ajaxdata-cbmm-ajax-urldata-cbmm-noncecbmm_admin_ajax_objectcbmm_frontend_ajax_objectcbmm_nonce/wp-json/cloudbridge-mattermost/v1/data