Theme Blvd WPML Bridge Security & Risk Analysis

wordpress.org/plugins/theme-blvd-wpml-bridge

This plugin adds additional WPML compatibility for Theme Blvd themes.

200 active installs v2.0.1 PHP + WP + Updated Mar 20, 2014
languagelocalizationmultilingualthemeblvdwpml
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Theme Blvd WPML Bridge Safe to Use in 2026?

Generally Safe

Score 85/100

Theme Blvd WPML Bridge has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The plugin 'theme-blvd-wpml-bridge' v2.0.1 exhibits a generally strong security posture based on the static analysis, with no apparent entry points that are unprotected. The absence of AJAX handlers, REST API routes, shortcodes, and cron events without proper authorization significantly reduces the plugin's attack surface. Furthermore, the code signals indicate a positive trend in security practices, with no dangerous functions, file operations, or external HTTP requests identified. All SQL queries are correctly prepared, mitigating the risk of SQL injection vulnerabilities.

However, a notable concern arises from the taint analysis, which reveals three flows with unsanitized paths. While these are not classified as critical or high severity, the presence of unsanitized paths in any context suggests a potential for vulnerabilities if user-supplied data is not handled with sufficient care. The output escaping also shows room for improvement, with only 37% of outputs being properly escaped, leaving a significant portion potentially vulnerable to cross-site scripting (XSS) attacks. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator of past security diligence. This suggests a potential for the plugin to be secure if the identified taint and output escaping issues are addressed.

In conclusion, the plugin demonstrates good practices in several key areas, particularly in minimizing its attack surface and handling database interactions securely. The lack of historical vulnerabilities is also a strong positive. The primary weaknesses lie in the taint flows with unsanitized paths and the low percentage of properly escaped output. Addressing these specific areas should be the focus for improving the plugin's security.

Key Concerns

  • Unsanitized paths found in taint analysis
  • Low percentage of properly escaped output
Vulnerabilities
None known

Theme Blvd WPML Bridge Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Theme Blvd WPML Bridge Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

37% escaped27 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
optionsframework_page (includes\legacy.php:624)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Theme Blvd WPML Bridge Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 31
actionthemeblvd_wpml_navincludes\frontend.php:61
actiontemplate_redirectincludes\legacy.php:35
filterthemeblvd_frontend_configincludes\legacy.php:45
actionafter_setup_themeincludes\legacy.php:48
actionthemeblvd_breadcrumbsincludes\legacy.php:311
actionthemeblvd_breadcrumbsincludes\legacy.php:313
actionadmin_menuincludes\legacy.php:363
actionafter_setup_themeincludes\legacy.php:367
actionadmin_print_styles-appearance_page_themeblvd_widget_areasincludes\legacy.php:447
actionadmin_print_styles-toplevel_page_themeblvd_builderincludes\legacy.php:448
actionadmin_print_styles-toplevel_page_themeblvd_slidersincludes\legacy.php:449
actionadmin_print_styles-appearance_page_options-frameworkincludes\legacy.php:452
actionadmin_print_styles-appearance_page_sidebar_blvdincludes\legacy.php:453
actionadmin_print_styles-toplevel_page_builder_blvdincludes\legacy.php:454
actionadmin_print_styles-toplevel_page_slider_blvdincludes\legacy.php:455
actionadmin_initincludes\legacy.php:459
actionthemeblvd_admin_module_headerincludes\legacy.php:808
actionadmin_initincludes\legacy.php:858
actionadmin_menuincludes\legacy.php:859
actioninitincludes\legacy.php:863
actionplugins_loadedtheme-blvd-wpml-bridge.php:51
filterthemeblvd_option_idtheme-blvd-wpml-bridge.php:132
actionafter_setup_themetheme-blvd-wpml-bridge.php:135
actionafter_setup_themetheme-blvd-wpml-bridge.php:138
actionafter_setup_themetheme-blvd-wpml-bridge.php:141
actionthemeblvd_breadcrumbstheme-blvd-wpml-bridge.php:230
filterthemeblvd_theme_options_argstheme-blvd-wpml-bridge.php:270
actionadmin_inittheme-blvd-wpml-bridge.php:274
actionthemeblvd_admin_module_headertheme-blvd-wpml-bridge.php:278
actionadmin_enqueue_scriptstheme-blvd-wpml-bridge.php:279
actioninittheme-blvd-wpml-bridge.php:282
Maintenance & Trust

Theme Blvd WPML Bridge Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedMar 20, 2014
PHP min version
Downloads43K

Community Trust

Rating100/100
Number of ratings2
Active installs200
Developer Profile

Theme Blvd WPML Bridge Developer Profile

Jason

22 plugins · 8K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
3363 days
View full developer profile
Detection Fingerprints

How We Detect Theme Blvd WPML Bridge

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/theme-blvd-wpml-bridge/css/admin.css/wp-content/plugins/theme-blvd-wpml-bridge/js/admin.js/wp-content/plugins/theme-blvd-wpml-bridge/js/themeblvd-wpml-bridge.js
Script Paths
/wp-content/plugins/theme-blvd-wpml-bridge/js/admin.js/wp-content/plugins/theme-blvd-wpml-bridge/js/themeblvd-wpml-bridge.js
Version Parameters
theme-blvd-wpml-bridge/css/admin.css?ver=theme-blvd-wpml-bridge/js/admin.js?ver=theme-blvd-wpml-bridge/js/themeblvd-wpml-bridge.js?ver=

HTML / DOM Fingerprints

CSS Classes
tb-wpml-bridge-optionstb-wpml-bridge-header
HTML Comments
<!-- Theme Blvd WPML Bridge v2.0.1 -->
Data Attributes
data-tb-wpml-bridge
JS Globals
ThemeBlvdWpmlBridge
FAQ

Frequently Asked Questions about Theme Blvd WPML Bridge