
Wbcom Designs – BuddyPress Post from Anywhere Security & Risk Analysis
wordpress.org/plugins/activity-link-preview-for-buddypressLet members post activity updates from any page. Add the Post From Anywhere block or the [bppfa_postform] shortcode where you want the form.
Is Wbcom Designs – BuddyPress Post from Anywhere Safe to Use in 2026?
Generally Safe
Score 98/100Wbcom Designs – BuddyPress Post from Anywhere has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'activity-link-preview-for-buddypress' plugin version 1.7.3 exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, 100% usage of prepared statements for SQL queries, and proper output escaping are all positive indicators. The presence of a nonce check and a file operation, while noted, do not immediately suggest critical vulnerabilities without further context, especially since there are no unauthenticated entry points identified in the attack surface analysis.
However, the taint analysis reveals two flows with unsanitized paths, which, although not categorized as critical or high severity in this report, warrant careful consideration. These unsanitized paths could potentially lead to unexpected behavior or vulnerabilities if exploited, especially in combination with other factors not immediately apparent from this report. The vulnerability history shows a past high-severity SSRF vulnerability, which is a significant concern. While this specific vulnerability is reported as patched, its occurrence suggests a potential area of weakness within the plugin's code that attackers might seek to exploit again in different forms.
In conclusion, while the plugin implements several strong security practices, the presence of unsanitized taint flows and a history of significant vulnerabilities like SSRF highlight areas for continued vigilance and potential improvement. The lack of capability checks on the single identified entry point is also a minor concern, as it implies that any authenticated user might be able to trigger this functionality.
Key Concerns
- Taint flows with unsanitized paths found
- No capability checks on entry points
- Past high severity SSRF vulnerability history
Wbcom Designs – BuddyPress Post from Anywhere Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Wbcom Designs - Activity Link Preview For BuddyPress <= 1.4.4 - Unauthenticated Server-Side Request Forgery
Wbcom Designs – BuddyPress Post from Anywhere Release Timeline
Wbcom Designs – BuddyPress Post from Anywhere Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Wbcom Designs – BuddyPress Post from Anywhere Attack Surface
AJAX Handlers 1
WordPress Hooks 13
Maintenance & Trust
Wbcom Designs – BuddyPress Post from Anywhere Maintenance & Trust
Maintenance Signals
Community Trust
Wbcom Designs – BuddyPress Post from Anywhere Alternatives
Wbcom Designs – BuddyPress Post from Anywhere
bp-post-from-anywhere
Let members post activity updates from any page. Add the Post From Anywhere block or the [bppfa_postform] shortcode where you want the form.
BuddyPress Builder for Elementor – BuddyBuilder
stax-buddy-builder
BuddyPress builder for Elementor — design member profiles, group pages, activity feeds and directories with drag & drop.
BuddyKit – Additional features for BuddyPress
buddykit
BuddyKit adds several features like Live Notifications and Media Activities to your BuddyPress powered websites.
Re-post Activity for BuddyPress
bp-repost-activity
Re-Post an Activity from activity stream. Re-post an activity to your group and personal activity.
Activity Feed Anywhere For BuddyBoss
activity-feed-anywhere-for-buddyboss
Activity Feed Anywhere For BuddyBoss adds a native BuddyBoss activity post box and/or feed on any page.
Wbcom Designs – BuddyPress Post from Anywhere Developer Profile
5 plugins · 330 total installs
How We Detect Wbcom Designs – BuddyPress Post from Anywhere
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/activity-link-preview-for-buddypress/assets/css/bp-activity-link-preview.css/wp-content/plugins/activity-activity-link-preview-for-buddypress/assets/js/bp-activity-link-preview.jshttps://platform.twitter.com/widgets.jshttps://connect.facebook.net/en_US/sdk.js#xfbml=1&version=v21.0activity-link-preview-for-buddypress/assets/css/bp-activity-link-preview.css?ver=activity-link-preview-for-buddypress/assets/js/bp-activity-link-preview.js?ver=HTML / DOM Fingerprints
bp_activity_link_preview/wp-json/bp-activity-link-preview/v1/activity/