
Fetch SPAD Security & Risk Analysis
wordpress.org/plugins/fetch-spad⚠️ DEPRECATED PLUGIN - PLEASE MIGRATE This plugin is being retired. Please use Fetch Meditation instead: https://wordpress.
Is Fetch SPAD Safe to Use in 2026?
Generally Safe
Score 100/100Fetch SPAD has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'fetch-spad' v1.4.0 demonstrates a generally strong security posture based on the provided static analysis. The code adheres to several best practices, including 100% proper output escaping and the use of prepared statements for all SQL queries. The presence of a nonce check is also a positive indicator. The attack surface appears minimal, with only one shortcode identified and no unprotected entry points. Taint analysis revealed no issues, and there is no recorded vulnerability history.
However, a key concern is the complete absence of capability checks. While there are no identified unprotected AJAX handlers or REST API routes, the lack of capability checks on the shortcode or any other potential entry points means that any authenticated user, regardless of their role or permissions, could potentially interact with the plugin's functionality. This could lead to unintended consequences or information disclosure depending on what the shortcode does. The bundling of Guzzle, while common, also warrants attention to ensure it is kept updated to avoid potential downstream vulnerabilities if the library itself has known issues.
Overall, the plugin is well-implemented with respect to common web vulnerabilities like SQL injection and XSS. The primary weakness lies in the granular access control, or lack thereof, which is a significant oversight for any plugin interacting with user actions or data. The absence of past vulnerabilities is encouraging but should not lead to complacency, especially given the identified access control gap.
Key Concerns
- Missing capability checks
- Bundled library (Guzzle) without version info
Fetch SPAD Security Vulnerabilities
Fetch SPAD Code Analysis
Bundled Libraries
Output Escaping
Fetch SPAD Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Fetch SPAD Maintenance & Trust
Maintenance Signals
Community Trust
Fetch SPAD Alternatives
Bread
bread
A web-based tool that creates, maintains and generates a PDF meeting list from BMLT.
crouton
crouton
crouton provides a UI and more for view recovery meetings as stored in a Basic Meeting List Toolbox (BMLT) database.
Fetch JFT
fetch-jft
Fetch JFT is a plugin that pulls the Just For Today from jftna.org and puts it on your page or post.
Fetch Meditation
fetch-meditation
Fetch Meditation is a plugin that pulls either the Spiritual Principle A Day or Just For Today and puts it on your page or post.
List Locations BMLT
list-locations-bmlt
List Locations BMLT is a plugin that returns all unique towns or counties from your BMLT server for a given service body on your site.
Fetch SPAD Developer Profile
10 plugins · 370 total installs
How We Detect Fetch SPAD
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fetch-spad/css/fetch-spad.css/wp-content/plugins/fetch-spad/js/fetch-spad.jsfetch-spad/css/fetch-spad.css?ver=1.0.0fetch-spad/js/fetch-spad.js?ver=HTML / DOM Fingerprints
spadspad-rendered-elementspad-tableid="spad-container"class="spad-rendered-element"id="spad-content-1"class="spad-rendered-element"id="spad-date"class="spad-rendered-element"+32 more[spad]