
First response Security & Risk Analysis
wordpress.org/plugins/first-responseProvides a "911 calls" post type, allowing fire and ems companies to list calls they are dispatched for.
Is First response Safe to Use in 2026?
Generally Safe
Score 85/100First response has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'first-response' plugin v1.1 exhibits a mixed security posture. On one hand, the static analysis reveals a notably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all detected SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, which are positive indicators. However, a significant concern arises from the complete lack of output escaping, as 100% of the 8 detected output instances are not properly escaped. This presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the WordPress frontend or backend.
The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the lack of critical taint flows and dangerous functions, suggests a generally stable codebase from a historical perspective. However, the absence of vulnerability history should not be interpreted as a guarantee of future security. The significant flaw in output escaping, coupled with zero nonce and capability checks, indicates a lack of basic security hardening measures that could be exploited.
In conclusion, while 'first-response' v1.1 benefits from a limited attack surface and secure database interactions, the severe deficiency in output escaping is a critical weakness that severely undermines its overall security. The absence of nonce and capability checks further exacerbates this risk. Despite a clean vulnerability history, the identified code issues present a tangible and immediate risk to users.
Key Concerns
- Unescaped output found
- Missing nonce checks
- Missing capability checks
First response Security Vulnerabilities
First response Release Timeline
First response Code Analysis
SQL Query Safety
Output Escaping
First response Attack Surface
WordPress Hooks 2
Maintenance & Trust
First response Maintenance & Trust
Maintenance Signals
Community Trust
First response Alternatives
Conditional Menus
conditional-menus
This plugin enables you to set conditional menus per posts, pages, categories, archive pages, etc.
GS Portfolio for Envato
gs-envato-portfolio
Best Responsive Envato Portfolio Plugin to display Themeforest & Codecanyon Items.
Themify Icons
themify-icons
Nifty plugin that enables you to use the Themify Icons (https://themify.me/themify-icons) font on your site.
Page Specific Menu Items
page-specific-menu-items
Allows user to select menu items page wise.
Einsatzverwaltung
einsatzverwaltung
Public incident reports for fire departments and other rescue services
First response Developer Profile
2 plugins · 20 total installs
How We Detect First response
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
call<h3>Importing calls since