Hosted JFT Security & Risk Analysis

wordpress.org/plugins/hosted-jft

Hosted JFT is a plugin that allows an NA Community to host their own translated version of the JFT. Add the [hosted_jft]

0 active installs v1.0.3 PHP + WP + Updated May 17, 2023
hosted-jftjftjust-for-todaynanarcotics-anonymous
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hosted JFT Safe to Use in 2026?

Generally Safe

Score 85/100

Hosted JFT has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "hosted-jft" plugin v1.0.3 exhibits a generally positive security posture based on the static analysis provided. The absence of dangerous functions, file operations, external HTTP requests, and a complete reliance on prepared statements for SQL queries are strong indicators of good development practices. The plugin also scores well on output escaping with 44% of outputs properly handled, which is a reasonable starting point, though further improvement is always beneficial. The vulnerability history is also a significant strength, with no known CVEs recorded, suggesting a history of secure development or thorough vetting.

However, there are areas that warrant attention. The analysis indicates zero nonce checks and zero capability checks across all entry points. While the static analysis reports no unprotected entry points (AJAX handlers, REST API routes, shortcodes, cron events), the absence of explicit capability checks and nonce verification on any code signals is a significant concern. This leaves potential avenues for unauthorized actions or cross-site request forgery (CSRF) if any of the 1 entry point (shortcode) could be manipulated without proper authorization checks. The taint analysis showing zero flows is good, but it's important to note that the total flows analyzed is also zero, which might indicate limited scope or complexity in the plugin's operation, not necessarily a guarantee of perfect taint handling if more complex interactions were present.

In conclusion, "hosted-jft" v1.0.3 has several strong security foundations, particularly in its SQL handling and lack of historical vulnerabilities. Nevertheless, the complete absence of nonce and capability checks across its entry points represents a notable weakness that could be exploited. The plugin is relatively secure but has clear room for improvement in authorization and authentication mechanisms for its accessible features.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
  • Output escaping only 44% proper
Vulnerabilities
None known

Hosted JFT Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Hosted JFT Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

44% escaped25 total outputs
Attack Surface

Hosted JFT Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[hosted_jft] hosted-jft-plugin.php:129
WordPress Hooks 4
actionadmin_initadmin\hosted-jft-dashboard.php:14
actionadmin_menuhosted-jft-plugin.php:17
actionpre_get_postshosted-jft-plugin.php:95
actionwidgets_inithosted-jft-plugin.php:133
Maintenance & Trust

Hosted JFT Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedMay 17, 2023
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Hosted JFT Developer Profile

pjaudiomv

10 plugins · 370 total installs

99
trust score
Avg Security Score
98/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Hosted JFT

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
spo-titlejft-widget-titlejft-widget-excerptjft-widget-link
HTML Comments
START Hosted JFT Widget END Hosted JFT Widget
Data Attributes
hosted_jft_widget
REST Endpoints
/wp-json/hosted-jft/v1/get-jft
Shortcode Output
<div class="spo-title"><h2 class="spo-title"><div class="jft-widget-title"><div class="jft-widget-excerpt"><a href="
FAQ

Frequently Asked Questions about Hosted JFT