bbp buddypress profile information Security & Risk Analysis

wordpress.org/plugins/bbp-buddypress-profile-information

For buddypress/bbPress - Displays any combination of up to 4 buddypress field under the authors avatar in topics and replies

70 active installs v1.3 PHP + WP + Updated Dec 5, 2025
bbpbbpressbuddypressforumprofile
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is bbp buddypress profile information Safe to Use in 2026?

Generally Safe

Score 100/100

bbp buddypress profile information has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The plugin "bbp-buddypress-profile-information" v1.3 exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The complete absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests indicates a well-contained codebase. The use of prepared statements for all SQL queries is a significant strength, mitigating the risk of SQL injection vulnerabilities. Furthermore, the lack of any recorded CVEs, either past or present, suggests a history of secure development and maintenance.

However, there are notable areas of concern. The fact that only 14% of output is properly escaped is a significant weakness. This leaves the plugin vulnerable to Cross-Site Scripting (XSS) attacks if user-supplied data is directly rendered without sufficient sanitization. The absence of any capability checks or nonce checks across all entry points (AJAX, REST API, shortcodes, cron events) is also a critical oversight. This means that any authenticated user, regardless of their role or permissions, could potentially trigger plugin functionality, leading to unauthorized actions or data manipulation. The zero taint analysis results are positive, but this could be misleading if the taint analysis tool had limited visibility or was unable to track the flow of data through the unescaped outputs and lack of capability checks.

In conclusion, while the plugin avoids common pitfalls like raw SQL and dangerous functions, the severe lack of output escaping and the absence of authorization checks on all entry points present substantial security risks. The vulnerability history is clean, but this doesn't negate the inherent weaknesses identified in the code analysis. The plugin needs significant attention to its input validation and authorization mechanisms to be considered truly secure.

Key Concerns

  • Low output escaping percentage
  • No capability checks on entry points
  • No nonce checks on entry points
Vulnerabilities
None known

bbp buddypress profile information Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

bbp buddypress profile information Release Timeline

v1.3Current
v1.2
v1.1
v1.0
Code Analysis
Analyzed Apr 16, 2026

bbp buddypress profile information Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
8 prepared
Unescaped Output
24
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared8 total queries

Output Escaping

14% escaped28 total outputs
Attack Surface

bbp buddypress profile information Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionbbp_theme_after_reply_author_detailsincludes/display.php:8
actionadmin_initincludes/settings.php:247
actionadmin_menuincludes/settings.php:255
Maintenance & Trust

bbp buddypress profile information Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 5, 2025
PHP min version
Downloads11K

Community Trust

Rating100/100
Number of ratings5
Active installs70
Developer Profile

bbp buddypress profile information Developer Profile

Robin W

9 plugins · 8K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
312 days
View full developer profile
Detection Fingerprints

How We Detect bbp buddypress profile information

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bbp-buddypress-profile-information/css/bbp-bp-profile-info.css/wp-content/plugins/bbp-buddypress-profile-information/js/bbp-bp-profile-info.js
Script Paths
/wp-content/plugins/bbp-buddypress-profile-information/js/bbp-bp-profile-info.js
Version Parameters
bbp-buddypress-profile-information/css/bbp-bp-profile-info.css?ver=bbp-buddypress-profile-information/js/bbp-bp-profile-info.js?ver=

HTML / DOM Fingerprints

CSS Classes
bbp-bp-profile-info-avatar-wrapper
JS Globals
rbi_settings
FAQ

Frequently Asked Questions about bbp buddypress profile information