Custom Bulleted Lists Security & Risk Analysis

wordpress.org/plugins/custom-bulleted-lists

Custom Bullet Lists: Write attractive and visually appealing content using custom bullet lists.

300 active installs v1.1 PHP + WP 4.6+ Updated Jul 24, 2017
bullet-pointsbulletscustom-bullet-listscustom-bulletscustom-lists
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom Bulleted Lists Safe to Use in 2026?

Generally Safe

Score 85/100

Custom Bulleted Lists has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The custom-bulleted-lists plugin version 1.1 demonstrates a strong security posture based on the provided static analysis. The complete absence of identified attack surface points (AJAX handlers, REST API routes, shortcodes, cron events) and the lack of dangerous function calls or unsanitized taint flows are highly positive indicators. Furthermore, the consistent use of prepared statements for SQL queries and proper output escaping suggests a developer who adheres to secure coding practices for data handling and presentation. The presence of capability checks, even with a small number, indicates some level of access control implementation.

However, the analysis does reveal a few potential areas of concern that, while not immediately exploitable based on the data, warrant attention. The complete lack of nonces, AJAX handlers, and REST API routes might simply mean these features are not implemented. If any future functionality is added that utilizes these mechanisms, the absence of existing checks could lead to vulnerabilities if not implemented with security in mind from the outset. The vulnerability history being entirely clean is a significant strength, implying a history of secure development or effective patching. Overall, this plugin appears secure for its current feature set, but future development should prioritize robust security measures for any new entry points or complex functionalities.

Key Concerns

  • No nonce checks present
  • No AJAX handlers with auth checks
  • No REST API routes with permission callbacks
Vulnerabilities
None known

Custom Bulleted Lists Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Custom Bulleted Lists Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Custom Bulleted Lists Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_headcustom-bulleted-lists.php:14
filtermce_external_pluginscustom-bulleted-lists.php:22
filtermce_buttonscustom-bulleted-lists.php:23
actionwp_enqueue_scriptscustom-bulleted-lists.php:40
actionadmin_enqueue_scriptscustom-bulleted-lists.php:49
actionwp_enqueue_scriptscustom-bulleted-lists.php:52
filtermce_csscustom-bulleted-lists.php:60
Maintenance & Trust

Custom Bulleted Lists Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedJul 24, 2017
PHP min version
Downloads5K

Community Trust

Rating60/100
Number of ratings2
Active installs300
Alternatives

Custom Bulleted Lists Alternatives

No alternatives data available yet.

Developer Profile

Custom Bulleted Lists Developer Profile

Janmejai

2 plugins · 330 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom Bulleted Lists

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/custom-bulleted-lists/js/wcb-buttons.js/wp-content/plugins/custom-bulleted-lists/css/style.css
Script Paths
/wp-content/plugins/custom-bulleted-lists/js/wcb-buttons.js
Version Parameters
custom-bulleted-lists/css/style.css?ver=custom-bulleted-lists/js/wcb-buttons.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Custom Bulleted Lists