
bbPress Top Contributors Security & Risk Analysis
wordpress.org/plugins/bbpress-top-contributorsShortcode to show the authors that have posted more
Is bbPress Top Contributors Safe to Use in 2026?
Generally Safe
Score 85/100bbPress Top Contributors has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bbpress-top-contributors" plugin version 0.1 exhibits a mixed security posture. On the positive side, the code avoids dangerous functions, external HTTP requests, and file operations. All identified SQL queries utilize prepared statements, and there are no recorded vulnerabilities or CVEs, suggesting a potentially well-maintained or simple codebase. However, significant concerns arise from the lack of output escaping. With 5 total outputs and 0% properly escaped, this presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts through plugin outputs. Additionally, the absence of nonce checks and capability checks on its single shortcode entry point is a notable weakness, potentially exposing it to CSRF attacks or unauthorized access to its functionality, even though no direct AJAX or REST API routes are exposed without checks. The taint analysis showing zero flows might be due to the limited complexity of the plugin or insufficient analysis depth, but the identified weaknesses in output handling and access control are substantial enough to warrant caution.
Key Concerns
- Unescaped output detected
- Missing nonce checks on shortcode
- Missing capability checks on shortcode
bbPress Top Contributors Security Vulnerabilities
bbPress Top Contributors Code Analysis
SQL Query Safety
Output Escaping
bbPress Top Contributors Attack Surface
Shortcodes 1
Maintenance & Trust
bbPress Top Contributors Maintenance & Trust
Maintenance Signals
Community Trust
bbPress Top Contributors Alternatives
bbPress Popular Topics
bbpress-popular-topics
Shortcode to show the topics with more replies
bbPress – Report Content
bbpress-report-content
Give your bbPress forum users the ability to report inappropriate content or spam in topics or replies.
bbPress New Topics
bbpress-new-topics
Displays a "new" label on topics that are unread or have unread replies for all keymasters and moderators.
bbPress Pencil Unread
bbpress-pencil-unread
bbPress Pencil Unread display which bbPress forums/topics have already been read by the user.
bbPress Protected Forums
bbpress-protected-forums
Disables new topic creation in some forums for determined roles.
bbPress Top Contributors Developer Profile
2 plugins · 20 total installs
How We Detect bbPress Top Contributors
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
eachbyimageauthorpostsrole<div class ="each"><span class ="by"> <span class ="image"><span class ="author"><a href =></a></span><span class ="posts"> posts</span><span class ="role">