
Hosted JFT Security & Risk Analysis
wordpress.org/plugins/hosted-jftHosted JFT is a plugin that allows an NA Community to host their own translated version of the JFT. Add the [hosted_jft]
Is Hosted JFT Safe to Use in 2026?
Generally Safe
Score 85/100Hosted JFT has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hosted-jft" plugin v1.0.3 exhibits a generally positive security posture based on the static analysis provided. The absence of dangerous functions, file operations, external HTTP requests, and a complete reliance on prepared statements for SQL queries are strong indicators of good development practices. The plugin also scores well on output escaping with 44% of outputs properly handled, which is a reasonable starting point, though further improvement is always beneficial. The vulnerability history is also a significant strength, with no known CVEs recorded, suggesting a history of secure development or thorough vetting.
However, there are areas that warrant attention. The analysis indicates zero nonce checks and zero capability checks across all entry points. While the static analysis reports no unprotected entry points (AJAX handlers, REST API routes, shortcodes, cron events), the absence of explicit capability checks and nonce verification on any code signals is a significant concern. This leaves potential avenues for unauthorized actions or cross-site request forgery (CSRF) if any of the 1 entry point (shortcode) could be manipulated without proper authorization checks. The taint analysis showing zero flows is good, but it's important to note that the total flows analyzed is also zero, which might indicate limited scope or complexity in the plugin's operation, not necessarily a guarantee of perfect taint handling if more complex interactions were present.
In conclusion, "hosted-jft" v1.0.3 has several strong security foundations, particularly in its SQL handling and lack of historical vulnerabilities. Nevertheless, the complete absence of nonce and capability checks across its entry points represents a notable weakness that could be exploited. The plugin is relatively secure but has clear room for improvement in authorization and authentication mechanisms for its accessible features.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- Output escaping only 44% proper
Hosted JFT Security Vulnerabilities
Hosted JFT Code Analysis
Output Escaping
Hosted JFT Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Hosted JFT Maintenance & Trust
Maintenance Signals
Community Trust
Hosted JFT Alternatives
Fetch JFT
fetch-jft
Fetch JFT is a plugin that pulls the Just For Today from jftna.org and puts it on your page or post.
Bread
bread
A web-based tool that creates, maintains and generates a PDF meeting list from BMLT.
crouton
crouton
crouton provides a UI and more for view recovery meetings as stored in a Basic Meeting List Toolbox (BMLT) database.
Fetch Meditation
fetch-meditation
Fetch Meditation is a plugin that pulls either the Spiritual Principle A Day or Just For Today and puts it on your page or post.
List Locations BMLT
list-locations-bmlt
List Locations BMLT is a plugin that returns all unique towns or counties from your BMLT server for a given service body on your site.
Hosted JFT Developer Profile
10 plugins · 370 total installs
How We Detect Hosted JFT
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
spo-titlejft-widget-titlejft-widget-excerptjft-widget-link START Hosted JFT Widget END Hosted JFT Widget hosted_jft_widget/wp-json/hosted-jft/v1/get-jft<div class="spo-title"><h2 class="spo-title"><div class="jft-widget-title"><div class="jft-widget-excerpt"><a href="