
Supernifty Bublz Security & Risk Analysis
wordpress.org/plugins/supernifty-bublzClick anything on your site. Pin a task to it. Track it on a kanban board. Bug reporting and feedback built into WordPress.
Is Supernifty Bublz Safe to Use in 2026?
Generally Safe
Score 100/100Supernifty Bublz has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "supernifty-bublz" plugin v1.0.55 exhibits a generally strong security posture based on the static analysis. A significant positive is the complete absence of raw SQL queries, with all 102 SQL queries utilizing prepared statements. Furthermore, all 234 output operations are properly escaped, and all 15 AJAX handlers have nonce checks in place. The plugin also demonstrates robust access control with 11 capability checks. The lack of any recorded vulnerabilities in its history is a very positive indicator of the developer's commitment to security.
However, there are a few areas that warrant attention. The taint analysis revealed 3 flows with unsanitized paths, all of which are classified as High severity. While these haven't manifested as public CVEs or been addressed in the historical data, they represent potential avenues for attack if exploited. The presence of file operations (9) and external HTTP requests (1) also represent potential, albeit limited, attack vectors that should be monitored for any future hardening. The absence of bundled libraries is a strength, as it avoids risks associated with outdated or vulnerable dependencies.
In conclusion, "supernifty-bublz" v1.0.55 is a well-developed plugin from a security perspective, with excellent adherence to fundamental WordPress security practices like prepared statements and output escaping. The primary concern lies with the identified high-severity taint flows, which, though unexploited historically, require careful monitoring and potential remediation to ensure continued security. The plugin's low attack surface and lack of known vulnerabilities are significant strengths.
Key Concerns
- High severity taint flows with unsanitized paths
- File operations present
- External HTTP requests present
Supernifty Bublz Security Vulnerabilities
Supernifty Bublz Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Supernifty Bublz Attack Surface
AJAX Handlers 15
WordPress Hooks 20
Maintenance & Trust
Supernifty Bublz Maintenance & Trust
Maintenance Signals
Community Trust
Supernifty Bublz Alternatives
Atarim – Visual Feedback, Review & AI Collaboration
atarim-visual-collaboration
Make collecting feedback on WordPress sites MUCH faster and easier, with the visual collaboration tool used on over 120,000 websites worldwide.
Annotatr – Bug Reporting, Bug Tracking, Kanban Board and Project Management
annotatr
Visual feedback and bug tracking for WordPress. Capture, assign, and fix issues without leaving your site — no more chasing reports.
Webvizio
webvizio
The Ultimate Visual Feedback, Collaboration & Productivity Tool for Web Professionals.
Simple Commenter – Website Feedback tool
simple-commenter
The website feedback tool your clients will actually use. Collect visual feedback directly on your site—no training required.
SureFeedback Cloud
surefeedback-cloud
SureFeedback Cloud helps teams collect visual feedback on WordPress sites and designs. Fast client sharing, zero hosting needed.
Supernifty Bublz Developer Profile
1 plugin · 0 total installs
How We Detect Supernifty Bublz
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/supernifty-bublz/css/dist/free-styles.css/wp-content/plugins/supernifty-bublz/js/dist/free-scripts.js/wp-content/plugins/supernifty-bublz/js/dist/free-scripts.js/wp-content/plugins/supernifty-bublz/css/dist/free-styles.css?ver=/wp-content/plugins/supernifty-bublz/js/dist/free-scripts.js?ver=HTML / DOM Fingerprints
bublz-freebublz-admin-pagedata-bublz-ticket-uuiddata-bublz-iddata-bublz-ticket-namedata-bublz-titledata-bublz-descriptiondata-bublz-status+2 morewindow.bublzFreeOptions/wp-json/bublz/v1/tickets