
bbPress Move Topics Security & Risk Analysis
wordpress.org/plugins/bbp-move-topicsMove topics from one forum to another, convert post/comments into topic/replies in the same site. For the admin backend.
Is bbPress Move Topics Safe to Use in 2026?
Use With Caution
Score 55/100bbPress Move Topics has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "bbp-move-topics" plugin v1.1.6 exhibits a mixed security posture. On the positive side, the static analysis reveals a small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or proper permission checks. The plugin also demonstrates good practices by using prepared statements for all SQL queries and performing file operations or external HTTP requests. Nonce checks are present, though their coverage is limited to 2 instances. However, the plugin has a significant concern regarding output escaping, with only 11% of outputs being properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. This is further corroborated by its vulnerability history, which includes multiple high and medium severity CVEs, predominantly related to XSS, deserialization, and CSRF. The presence of an unpatched CVE is a critical red flag. The consistent pattern of past vulnerabilities, especially XSS, combined with poor output escaping in the current version, suggests a recurring weakness in sanitizing user-supplied data before rendering it in the browser. While the plugin has strengths in secure database interactions and a contained entry point, the persistent and severe output escaping issues and the unpatched CVE make it a significant security risk. Users should exercise extreme caution and ensure the plugin is updated to address any known vulnerabilities, particularly the unpatched one.
Key Concerns
- Unpatched CVE exists
- Low output escaping coverage (11%)
- Multiple high severity CVEs in history
- Limited nonce checks (2 instances)
bbPress Move Topics Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
bbPress Move Topics <= 1.1.6 - Reflected Cross-Site Scripting
bbPress Move Topics <= 1.1.4 - PHP Object Injection
bbPress Move Topics <= 1.1.4 - Cross-Site Request Forgery
bbPress Move Topics Release Timeline
bbPress Move Topics Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
bbPress Move Topics Attack Surface
WordPress Hooks 5
Maintenance & Trust
bbPress Move Topics Maintenance & Trust
Maintenance Signals
Community Trust
bbPress Move Topics Alternatives
One User Avatar | User Profile Picture
one-user-avatar
Use any image from your WordPress Media Library as a custom user avatar or user profile picture. Add your own Default Avatar.
Content Aware Sidebars – Fastest Widget Area Plugin
content-aware-sidebars
Display new sidebars on any post, page, category etc. Works with Classic Widgets, Block Widgets, and all themes!
wpForo Forum
wpforo
Number one WordPress forum plugin with AI features. Full-fledged forum solution with modern forum design. Community builder WordPress forum plugin.
Restrict User Access – Ultimate Membership & Content Protection
restrict-user-access
Create Access Levels and restrict any post, page, category, etc. Supports bbPress, BuddyPress, WooCommerce, WPML, and more.
bbp style pack
bbp-style-pack
For bbPress - Lets you style bbPress, and add display features
bbPress Move Topics Developer Profile
3 plugins · 210 total installs
How We Detect bbPress Move Topics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bbp-move-topics/js/bbpmt-script.js/wp-content/plugins/bbp-move-topics/css/bbpmt-style.css/wp-content/plugins/bbp-move-topics/js/bbpmt-script.jsbbp-move-topics/js/bbpmt-script.js?ver=bbp-move-topics/css/bbpmt-style.css?ver=HTML / DOM Fingerprints
bbpmtcbgroupbbpmt-forum-topicsbbpmtcbgroup_masterid="bbpmttopicform"id="bbpmt-forum-topics"id="bbpmtcbgroup_master"onchange="bbpmttoggleall(this,'bbpmtcbgroup')"id="destinationforum"name="sourceforum"+1 morebbpmttoggleall