
Activity Link Preview For BuddyPress Security & Risk Analysis
wordpress.org/plugins/activity-link-preview-for-buddypressBuddyPress activity link preview displays image, title and description from websites when links are shared in activity posts.
Is Activity Link Preview For BuddyPress Safe to Use in 2026?
Generally Safe
Score 98/100Activity Link Preview For BuddyPress has a strong security track record. Known vulnerabilities have been patched promptly.
The 'activity-link-preview-for-buddypress' plugin version 1.7.3 exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, 100% usage of prepared statements for SQL queries, and proper output escaping are all positive indicators. The presence of a nonce check and a file operation, while noted, do not immediately suggest critical vulnerabilities without further context, especially since there are no unauthenticated entry points identified in the attack surface analysis.
However, the taint analysis reveals two flows with unsanitized paths, which, although not categorized as critical or high severity in this report, warrant careful consideration. These unsanitized paths could potentially lead to unexpected behavior or vulnerabilities if exploited, especially in combination with other factors not immediately apparent from this report. The vulnerability history shows a past high-severity SSRF vulnerability, which is a significant concern. While this specific vulnerability is reported as patched, its occurrence suggests a potential area of weakness within the plugin's code that attackers might seek to exploit again in different forms.
In conclusion, while the plugin implements several strong security practices, the presence of unsanitized taint flows and a history of significant vulnerabilities like SSRF highlight areas for continued vigilance and potential improvement. The lack of capability checks on the single identified entry point is also a minor concern, as it implies that any authenticated user might be able to trigger this functionality.
Key Concerns
- Taint flows with unsanitized paths found
- No capability checks on entry points
- Past high severity SSRF vulnerability history
Activity Link Preview For BuddyPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Wbcom Designs - Activity Link Preview For BuddyPress <= 1.4.4 - Unauthenticated Server-Side Request Forgery
Activity Link Preview For BuddyPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Activity Link Preview For BuddyPress Attack Surface
AJAX Handlers 1
WordPress Hooks 13
Maintenance & Trust
Activity Link Preview For BuddyPress Maintenance & Trust
Maintenance Signals
Community Trust
Activity Link Preview For BuddyPress Alternatives
BuddyPress Edit Activity
buddypress-edit-activity
BuddyPress Edit Activity allows your members to edit their activity posts on the front-end of your BuddyPress-powered site.
BuddyKit – Additional features for BuddyPress
buddykit
BuddyKit adds several features like Live Notifications and Media Activities to your BuddyPress powered websites.
What's Hot Activity Tab for BuddyPress
bp-whats-hot
Adds a What's Hot tab to the BuddyPress activity stream.
Personalized Activity for Buddypress – Friends, Following, Admin
personalized-activity-for-buddypress-frfwa
Makes Buddypress Activity Personalized For Users, by Including Activity Feeds Only From Users They Are Friends With, Users They Are Following And Administrator of Your Community.
Open Graph and Twitter Card Tags
wonderm00ns-simple-facebook-open-graph-tags
Improve social media sharing by inserting Facebook Open Graph, Twitter Card, and SEO Meta Tags on your WordPress website pages, posts, WooCommerce pro …
Activity Link Preview For BuddyPress Developer Profile
5 plugins · 420 total installs
How We Detect Activity Link Preview For BuddyPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/activity-link-preview-for-buddypress/assets/css/bp-activity-link-preview.css/wp-content/plugins/activity-activity-link-preview-for-buddypress/assets/js/bp-activity-link-preview.jshttps://platform.twitter.com/widgets.jshttps://connect.facebook.net/en_US/sdk.js#xfbml=1&version=v21.0activity-link-preview-for-buddypress/assets/css/bp-activity-link-preview.css?ver=activity-link-preview-for-buddypress/assets/js/bp-activity-link-preview.js?ver=HTML / DOM Fingerprints
bp_activity_link_preview/wp-json/bp-activity-link-preview/v1/activity/