
Contacts BMLT Security & Risk Analysis
wordpress.org/plugins/contacts-bmltContacts BMLT is a plugin that displays helpline and website information about service bodies using the contacts_bmlt shortcode.
Is Contacts BMLT Safe to Use in 2026?
Generally Safe
Score 100/100Contacts BMLT has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "contacts-bmlt" plugin v1.3.2 demonstrates a generally positive security posture based on the provided static analysis and vulnerability history. It shows a commitment to secure coding practices by avoiding dangerous functions, all SQL queries utilizing prepared statements, and a single external HTTP request which is a common and often necessary feature. The presence of a nonce check is also a good sign. The lack of any recorded vulnerabilities or CVEs in its history further suggests a stable and secure offering.
However, there are areas for improvement. While the number of output escapes is relatively high, 28% of them are not properly escaped, introducing a potential risk of cross-site scripting (XSS) vulnerabilities if the unescaped output is user-controllable. The plugin also lacks capability checks on its single shortcode entry point, meaning any user, regardless of their role, could potentially execute the shortcode's functionality. This could lead to unintended behavior or information disclosure depending on what the shortcode does.
In conclusion, "contacts-bmlt" v1.3.2 is a relatively secure plugin with a clean vulnerability history and good use of prepared statements. The primary concerns lie in the unescaped output and the absence of capability checks on its shortcode. Addressing these specific issues would significantly enhance its overall security.
Key Concerns
- Unescaped output detected
- Shortcode lacks capability checks
Contacts BMLT Security Vulnerabilities
Contacts BMLT Code Analysis
Bundled Libraries
Output Escaping
Contacts BMLT Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Contacts BMLT Maintenance & Trust
Maintenance Signals
Community Trust
Contacts BMLT Alternatives
List Locations BMLT
list-locations-bmlt
List Locations BMLT is a plugin that returns all unique towns or counties from your BMLT server for a given service body on your site.
Upcoming Meetings BMLT
upcoming-meetings-bmlt
Upcoming Meetings BMLT is a plugin that displays the next 'N' number of meetings from the current time on your page or in a widget using the …
Temporary Closures BMLT
temporary-closures-bmlt
Temporary Closures BMLT is a plugin that displays a list of all meetings that have temporary closures. It can be used
Bread
bread
A web-based tool that creates, maintains and generates a PDF meeting list from BMLT.
crouton
crouton
crouton provides a UI and more for view recovery meetings as stored in a Basic Meeting List Toolbox (BMLT) database.
Contacts BMLT Developer Profile
10 plugins · 370 total installs
How We Detect Contacts BMLT
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contacts-bmlt/css/redmond/jquery-ui.css/wp-content/plugins/contacts-bmlt/css/chosen.min.css/wp-content/plugins/contacts-bmlt/js/chosen.jquery.min.js/wp-content/plugins/contacts-bmlt/js/contacts_bmlt_admin.js/wp-content/plugins/contacts-bmlt/css/contacts_bmlt.css/wp-content/plugins/contacts-bmlt/js/chosen.jquery.min.js/wp-content/plugins/contacts-bmlt/js/contacts_bmlt_admin.jscontacts-bmlt-admin-ui-css?ver=1.11.4chosen?ver=1.2contacts-bmlt-admin?ver=contacts-bmlt?ver=1.21HTML / DOM Fingerprints
[contacts_bmlt]