
Activity Feed Anywhere Security & Risk Analysis
wordpress.org/plugins/activity-feed-anywhereActivity Feed Anywhere adds a custom BuddyPress activity post box and/or feed on any page.
Is Activity Feed Anywhere Safe to Use in 2026?
Generally Safe
Score 100/100Activity Feed Anywhere has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "activity-feed-anywhere" v1.0.0 exhibits a strong security posture based on the provided static analysis. It has no detected dangerous functions, all SQL queries are prepared, and all output is properly escaped. Furthermore, there are no file operations, external HTTP requests, or taint vulnerabilities identified. The plugin also demonstrates good practice by including capability checks for its entry points.
Despite these positive findings, there are a few areas that warrant attention. The absence of nonce checks on the sole shortcode is a potential concern, as it means that the shortcode's functionality, if it performs any sensitive actions, could be vulnerable to Cross-Site Request Forgery (CSRF) attacks. The fact that there are no known CVEs and no recorded past vulnerabilities suggests a well-maintained codebase. However, the lack of taint analysis flows and the limited attack surface make it difficult to definitively assess deeper security risks.
Overall, the plugin appears to be well-developed from a security perspective, adhering to many best practices. The primary area for improvement is the addition of nonce checks to the shortcode to mitigate potential CSRF vulnerabilities. Without this, the plugin has a minor but addressable security weakness.
Key Concerns
- Missing nonce checks on shortcode
Activity Feed Anywhere Security Vulnerabilities
Activity Feed Anywhere Code Analysis
Output Escaping
Activity Feed Anywhere Attack Surface
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
Activity Feed Anywhere Maintenance & Trust
Maintenance Signals
Community Trust
Activity Feed Anywhere Alternatives
Activity Plus Reloaded for BuddyPress
bp-activity-plus-reloaded
Note: This plugin will be discontinued by March 31st, 2025 in favor of BuddyPress Attachment plugin. Please migrate to the new plugin before that date …
BuddyKit – Additional features for BuddyPress
buddykit
BuddyKit adds several features like Live Notifications and Media Activities to your BuddyPress powered websites.
BuddyPress Activity Privacy
buddypress-activity-privacy
BuddyPress Activity Privacy plugin add a privacy level to activity stream component.
NextCellent Simple History
ngg-simple-history
Add Simple History integration for NextCellent.
ActivityStream extension
activitystream-extension
ActivityStrea.ms feeds for WordPress (Atom and JSON(-LD))
Activity Feed Anywhere Developer Profile
4 plugins · 2K total installs
How We Detect Activity Feed Anywhere
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
activity-feed-anywheredata-bp-list="activity"<div id="buddypress" class="buddypress-wrap"><div id="activity-stream" class="activity" data-bp-list="activity"><div id="bp-ajax-loader">