
Fetch JFT Security & Risk Analysis
wordpress.org/plugins/fetch-jftFetch JFT is a plugin that pulls the Just For Today from jftna.org and puts it on your page or post.
Is Fetch JFT Safe to Use in 2026?
Generally Safe
Score 99/100Fetch JFT has a strong security track record. Known vulnerabilities have been patched promptly.
The "fetch-jft" plugin v1.9.1 exhibits a mixed security posture. On the positive side, the static analysis reveals a strong adherence to secure coding practices with 100% output escaping and no identified dangerous functions, file operations, or external HTTP requests. The limited attack surface, consisting of a single shortcode with no explicit auth checks, and the absence of taint analysis findings are also encouraging.
However, significant concerns arise from the vulnerability history. The presence of a previously disclosed medium-severity Cross-Site Scripting (XSS) vulnerability, even though currently patched, indicates a historical weakness in input sanitization or output encoding. The lack of nonce checks and capability checks for the identified entry points (shortcode) is a notable oversight, as these are fundamental security mechanisms for preventing unauthorized actions and ensuring input integrity.
While the current version shows improvements, the past XSS vulnerability and the absence of built-in authorization checks for its shortcode suggest potential areas for improvement. The plugin's security is heavily reliant on the fact that its sole entry point (shortcode) likely doesn't handle untrusted user input in a way that could immediately lead to issues, or that the XSS was fixed internally. A cautious approach is recommended, with ongoing monitoring for future vulnerabilities.
Key Concerns
- Medium severity XSS vulnerability historically
- No nonce checks on entry points
- No capability checks on entry points
- SQL queries not always prepared
Fetch JFT Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Fetch JFT <= 1.8.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
Fetch JFT Code Analysis
SQL Query Safety
Output Escaping
Fetch JFT Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Fetch JFT Maintenance & Trust
Maintenance Signals
Community Trust
Fetch JFT Alternatives
Hosted JFT
hosted-jft
Hosted JFT is a plugin that allows an NA Community to host their own translated version of the JFT. Add the [hosted_jft]
Bread
bread
A web-based tool that creates, maintains and generates a PDF meeting list from BMLT.
crouton
crouton
crouton provides a UI and more for view recovery meetings as stored in a Basic Meeting List Toolbox (BMLT) database.
Fetch Meditation
fetch-meditation
Fetch Meditation is a plugin that pulls either the Spiritual Principle A Day or Just For Today and puts it on your page or post.
List Locations BMLT
list-locations-bmlt
List Locations BMLT is a plugin that returns all unique towns or counties from your BMLT server for a given service body on your site.
Fetch JFT Developer Profile
10 plugins · 370 total installs
How We Detect Fetch JFT
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fetch-jft/css/jft.css/wp-content/plugins/fetch-jft/js/jft.jsfetch-jft/css/jft.cssfetch-jft/js/jft.jsHTML / DOM Fingerprints
id="language-container"id="layout-container"[jft]