Supernifty Bublz Security & Risk Analysis

wordpress.org/plugins/supernifty-bublz

Click anything on your site. Pin a task to it. Track it on a kanban board. Bug reporting and feedback built into WordPress.

0 active installs v1.0.54 PHP 8.1+ WP 6.4+ Updated Mar 14, 2026
bug-reportingclient-feedbackkanban-boardproject-managementvisual-feedback
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Supernifty Bublz Safe to Use in 2026?

Generally Safe

Score 100/100

Supernifty Bublz has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 20d ago
Risk Assessment

The "supernifty-bublz" plugin v1.0.55 exhibits a generally strong security posture based on the static analysis. A significant positive is the complete absence of raw SQL queries, with all 102 SQL queries utilizing prepared statements. Furthermore, all 234 output operations are properly escaped, and all 15 AJAX handlers have nonce checks in place. The plugin also demonstrates robust access control with 11 capability checks. The lack of any recorded vulnerabilities in its history is a very positive indicator of the developer's commitment to security.

However, there are a few areas that warrant attention. The taint analysis revealed 3 flows with unsanitized paths, all of which are classified as High severity. While these haven't manifested as public CVEs or been addressed in the historical data, they represent potential avenues for attack if exploited. The presence of file operations (9) and external HTTP requests (1) also represent potential, albeit limited, attack vectors that should be monitored for any future hardening. The absence of bundled libraries is a strength, as it avoids risks associated with outdated or vulnerable dependencies.

In conclusion, "supernifty-bublz" v1.0.55 is a well-developed plugin from a security perspective, with excellent adherence to fundamental WordPress security practices like prepared statements and output escaping. The primary concern lies with the identified high-severity taint flows, which, though unexploited historically, require careful monitoring and potential remediation to ensure continued security. The plugin's low attack surface and lack of known vulnerabilities are significant strengths.

Key Concerns

  • High severity taint flows with unsanitized paths
  • File operations present
  • External HTTP requests present
Vulnerabilities
None known

Supernifty Bublz Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Supernifty Bublz Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
102 prepared
Unescaped Output
0
234 escaped
Nonce Checks
15
Capability Checks
11
File Operations
9
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared102 total queries

Output Escaping

100% escaped234 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

11 flows3 with unsanitized paths
ajax_save_settings (settings.php:123)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Supernifty Bublz Attack Surface

Entry Points15
Unprotected0

AJAX Handlers 15

authwp_ajax_bublz_save_avatar_preferencepreferences.php:13
authwp_ajax_bublz_upload_custom_avatarpreferences.php:14
authwp_ajax_bublz_delete_custom_avatarpreferences.php:15
authwp_ajax_bublz_save_settingssettings.php:17
authwp_ajax_bublz_clear_transientssettings.php:18
authwp_ajax_bublz_clear_cachesettings.php:19
authwp_ajax_bublz_save_ticketsupernifty-bublz.php:45
authwp_ajax_bublz_update_sort_ordersupernifty-bublz.php:46
authwp_ajax_bublz_delete_ticketsupernifty-bublz.php:47
authwp_ajax_bublz_update_statussupernifty-bublz.php:48
authwp_ajax_bublz_update_prioritysupernifty-bublz.php:49
authwp_ajax_bublz_generate_namesupernifty-bublz.php:50
authwp_ajax_bublz_refresh_panelsupernifty-bublz.php:51
authwp_ajax_bublz_delete_orphaned_pro_datasupernifty-bublz.php:52
authwp_ajax_bublz_set_delete_preferencesupernifty-bublz.php:68
WordPress Hooks 20
actionadmin_initsettings.php:15
actionadmin_enqueue_scriptssettings.php:16
filteroption_page_capability_bublz_settings_groupsettings.php:20
filterpre_update_option_bublz_settingssettings.php:21
actionset_current_plugin_versionsupernifty-bublz.php:42
actionadmin_enqueue_scriptssupernifty-bublz.php:43
actionwp_enqueue_scriptssupernifty-bublz.php:44
actionadmin_footersupernifty-bublz.php:53
actionwp_footersupernifty-bublz.php:54
actionwp_footersupernifty-bublz.php:55
actionwp_footersupernifty-bublz.php:56
actionadmin_bar_menusupernifty-bublz.php:57
actionadmin_menusupernifty-bublz.php:58
actionadmin_initsupernifty-bublz.php:59
actionadmin_initsupernifty-bublz.php:60
actionadmin_initsupernifty-bublz.php:61
actionadmin_noticessupernifty-bublz.php:62
filteradmin_body_classsupernifty-bublz.php:63
actionadmin_enqueue_scriptssupernifty-bublz.php:67
actionadmin_noticessupernifty-bublz.php:1665
Maintenance & Trust

Supernifty Bublz Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 14, 2026
PHP min version8.1
Downloads131

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Supernifty Bublz Developer Profile

Supernifty

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Supernifty Bublz

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/supernifty-bublz/css/dist/free-styles.css/wp-content/plugins/supernifty-bublz/js/dist/free-scripts.js
Script Paths
/wp-content/plugins/supernifty-bublz/js/dist/free-scripts.js
Version Parameters
/wp-content/plugins/supernifty-bublz/css/dist/free-styles.css?ver=/wp-content/plugins/supernifty-bublz/js/dist/free-scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
bublz-freebublz-admin-page
Data Attributes
data-bublz-ticket-uuiddata-bublz-iddata-bublz-ticket-namedata-bublz-titledata-bublz-descriptiondata-bublz-status+2 more
JS Globals
window.bublzFreeOptions
REST Endpoints
/wp-json/bublz/v1/tickets
FAQ

Frequently Asked Questions about Supernifty Bublz