
bbPress Contacts Security & Risk Analysis
wordpress.org/plugins/bbp-contactsAllow your bbPress users to bookmark other users easily and view/search them through their bbP profiles.
Is bbPress Contacts Safe to Use in 2026?
Generally Safe
Score 85/100bbPress Contacts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The bbp-contacts v0.2.1 plugin demonstrates a mixed security posture. On the positive side, it avoids dangerous functions, exclusively uses prepared statements for SQL queries, has no file operations or external HTTP requests, and includes a reasonable number of nonce checks. The absence of known CVEs and vulnerability history is also a strong indicator of past security diligence. However, a significant concern arises from the attack surface analysis, which reveals two AJAX handlers, with one completely lacking authentication checks. This unprotected entry point presents a direct risk, as it could potentially be exploited by unauthenticated users. Furthermore, the taint analysis indicates two flows with unsanitized paths, which, although not classified as critical or high severity in this analysis, still warrant caution as they represent potential avenues for data manipulation or unintended behavior if exploited. The limited capability checks is also a weakness, suggesting that access to certain functionalities might not be adequately restricted.
Key Concerns
- Unprotected AJAX handler
- Flows with unsanitized paths (taint analysis)
- Missing capability checks
- Output escaping is not fully proper (74%)
bbPress Contacts Security Vulnerabilities
bbPress Contacts Code Analysis
Output Escaping
Data Flow Analysis
bbPress Contacts Attack Surface
AJAX Handlers 2
WordPress Hooks 9
Maintenance & Trust
bbPress Contacts Maintenance & Trust
Maintenance Signals
Community Trust
bbPress Contacts Alternatives
One User Avatar | User Profile Picture
one-user-avatar
Use any image from your WordPress Media Library as a custom user avatar or user profile picture. Add your own Default Avatar.
Restrict User Access – Ultimate Membership & Content Protection
restrict-user-access
Create Access Levels and restrict any post, page, category, etc. Supports bbPress, BuddyPress, WooCommerce, WPML, and more.
Simple Membership Custom Messages
simple-membership-custom-messages
Simple Membership Addon to customize various content protection messages.
BP Profile Search
bp-profile-search
Member search and member directories for BuddyPress and the BuddyBoss Platform.
Expire User Passwords
expire-user-passwords
Require certain users to change their passwords on a regular basis.
bbPress Contacts Developer Profile
12 plugins · 670 total installs
How We Detect bbPress Contacts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bbp-contacts/assets/css/style.css/wp-content/plugins/bbp-contacts/assets/js/bbp-contacts.js/wp-content/plugins/bbp-contacts/assets/js/bbp-contacts.jsbbp-contacts/assets/css/style.css?ver=bbp-contacts/assets/js/bbp-contacts.js?ver=HTML / DOM Fingerprints
bbpc-contacts-listdata-bbpc-nonceBBPC