Advanced XProfile Fields for BuddyPress Security & Risk Analysis

wordpress.org/plugins/advanced-xprofile-fields-for-buddypress

Enhance your BuddyPress profile fields with Advanced XProfile Fields for BuddyPress. Manage fields labels, validation and show fields in admin.

100 active installs v1.0.4.2 PHP 5.3+ WP 3.2+ Updated Apr 26, 2020
buddypressbuddypress-groupsbuddypress-profile-fieldgroupssocial-network
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Advanced XProfile Fields for BuddyPress Safe to Use in 2026?

Generally Safe

Score 85/100

Advanced XProfile Fields for BuddyPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The plugin "advanced-xprofile-fields-for-buddypress" version 1.0.4.2 exhibits a generally strong security posture based on the static analysis. The complete absence of identified dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the high percentage of properly escaped output (89%) suggests a good understanding of preventing cross-site scripting vulnerabilities. The limited attack surface with zero identified entry points, particularly those without authentication checks, is a significant strength. The single capability check is a minimal but present defense mechanism.

However, the static analysis reveals a critical gap: the complete lack of nonce checks across all identified entry points, which are zero in number. While there are no identified entry points to begin with, this finding suggests that if any were introduced or became accessible, they would lack a fundamental WordPress security mechanism for validating user intent and preventing CSRF attacks. The taint analysis did not identify any issues, but this is in the context of zero flows being analyzed, making it impossible to confirm the absence of taint vulnerabilities. The vulnerability history is also clean, with no recorded CVEs, which is positive but doesn't guarantee future safety.

In conclusion, the plugin demonstrates good practices in areas like SQL query sanitization and output escaping. The primary concern lies in the absence of nonce checks, which, despite the current lack of an exposed attack surface, represents a potential weakness that could be exploited if new entry points are added or discovered. The clean vulnerability history is a positive indicator of past security diligence.

Key Concerns

  • Nonce checks missing
Vulnerabilities
None known

Advanced XProfile Fields for BuddyPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Advanced XProfile Fields for BuddyPress Release Timeline

v1.0.4
Code Analysis
Analyzed Mar 16, 2026

Advanced XProfile Fields for BuddyPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
2
16 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

89% escaped18 total outputs
Attack Surface

Advanced XProfile Fields for BuddyPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionxprofile_field_after_contentboxsp-advanced-xprofile.php:54
actionxprofile_fields_saved_fieldsp-advanced-xprofile.php:55
filterbp_get_the_profile_field_namesp-advanced-xprofile.php:56
filterbp_has_profilesp-advanced-xprofile.php:57
filterbp_has_profilesp-advanced-xprofile.php:58
actionbp_after_profile_edit_contentsp-advanced-xprofile.php:59
actionbp_after_register_pagesp-advanced-xprofile.php:60
filtermanage_users_columnssp-advanced-xprofile.php:61
actionmanage_users_custom_columnsp-advanced-xprofile.php:62
actionbp_initsp-advanced-xprofile.php:400
actionplugins_loadedsp-advanced-xprofile.php:408
Maintenance & Trust

Advanced XProfile Fields for BuddyPress Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedApr 26, 2020
PHP min version5.3
Downloads13K

Community Trust

Rating84/100
Number of ratings5
Active installs100
Developer Profile

Advanced XProfile Fields for BuddyPress Developer Profile

SuitePlugins

19 plugins · 2K total installs

90
trust score
Avg Security Score
85/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Advanced XProfile Fields for BuddyPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-xprofile-fields-for-buddypress/admin/template/metabox.php

HTML / DOM Fingerprints

CSS Classes
sp-advanced-xprofile
Data Attributes
data-iddata-field-iddata-advanced-xprofile-labelsdata-advanced-xprofile-validationdata-advanced-xprofile-options
JS Globals
sp_advanced_xprofile_params
FAQ

Frequently Asked Questions about Advanced XProfile Fields for BuddyPress