
List Locations BMLT Security & Risk Analysis
wordpress.org/plugins/list-locations-bmltList Locations BMLT is a plugin that returns all unique towns or counties from your BMLT server for a given service body on your site.
Is List Locations BMLT Safe to Use in 2026?
Generally Safe
Score 100/100List Locations BMLT has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'list-locations-bmlt' v2.4.0 plugin exhibits a generally good security posture based on the provided static analysis. The absence of known CVEs and the complete reliance on prepared statements for SQL queries are strong indicators of secure coding practices in these areas. The plugin also appears to handle file operations and external HTTP requests with caution. However, the analysis reveals a weakness in output escaping, with only 55% of outputs being properly escaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed. Additionally, while the attack surface is small and there are no unprotected entry points, the lack of capability checks on the single shortcode is a concern. This means any authenticated user, regardless of their role, could potentially execute the shortcode, which might lead to unintended actions or information disclosure depending on the shortcode's functionality. The plugin's history of no recorded vulnerabilities is a positive sign, suggesting consistent security efforts, but the identified output escaping and capability check issues warrant attention.
Key Concerns
- Insufficient output escaping
- Missing capability checks on shortcode
List Locations BMLT Security Vulnerabilities
List Locations BMLT Code Analysis
Bundled Libraries
Output Escaping
List Locations BMLT Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
List Locations BMLT Maintenance & Trust
Maintenance Signals
Community Trust
List Locations BMLT Alternatives
Upcoming Meetings BMLT
upcoming-meetings-bmlt
Upcoming Meetings BMLT is a plugin that displays the next 'N' number of meetings from the current time on your page or in a widget using the …
Contacts BMLT
contacts-bmlt
Contacts BMLT is a plugin that displays helpline and website information about service bodies using the contacts_bmlt shortcode.
Temporary Closures BMLT
temporary-closures-bmlt
Temporary Closures BMLT is a plugin that displays a list of all meetings that have temporary closures. It can be used
Bread
bread
A web-based tool that creates, maintains and generates a PDF meeting list from BMLT.
crouton
crouton
crouton provides a UI and more for view recovery meetings as stored in a Basic Meeting List Toolbox (BMLT) database.
List Locations BMLT Developer Profile
10 plugins · 370 total installs
How We Detect List Locations BMLT
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/list-locations-bmlt/css/start/jquery-ui.css/wp-content/plugins/list-locations-bmlt/css/chosen.min.css/wp-content/plugins/list-locations-bmlt/css/list_locations.css/wp-content/plugins/list-locations-bmlt/js/chosen.jquery.min.js/wp-content/plugins/list-locations-bmlt/js/list_locations_admin.js/wp-content/plugins/list-locations-bmlt/js/list_locations_admin.jslist-locations-bmlt/css/start/jquery-ui.css?ver=list-locations-bmlt/css/chosen.min.css?ver=list-locations-bmlt/css/list_locations.css?ver=list-locations-bmlt/js/chosen.jquery.min.js?ver=list-locations-bmlt/js/list_locations_admin.js?ver=HTML / DOM Fingerprints
chosen-containerchosen-dropchosen-resultsdata-placeholder_option_multiple[list_locations]