
BP Activity Share Security & Risk Analysis
wordpress.org/plugins/bp-activity-shareUsing BP Activity Share plugin you can share any activity locally like we share any post in FaceBook.
Is BP Activity Share Safe to Use in 2026?
Generally Safe
Score 85/100BP Activity Share has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bp-activity-share" plugin version 1.5.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices in handling SQL queries by exclusively using prepared statements, and it has a clean vulnerability history with no known CVEs. The absence of dangerous functions, file operations, and external HTTP requests are also positive indicators. However, significant concerns arise from the attack surface analysis, which reveals two AJAX handlers, both lacking authentication checks. This presents a direct vulnerability, as any unauthenticated user could potentially interact with these endpoints.
The static analysis also indicates a strong emphasis on output escaping, with a high percentage of outputs being properly handled, and a single nonce check is present, which is a good practice for AJAX. The lack of critical or high severity taint flows is reassuring, suggesting that sensitive data is likely not being mishandled internally. Despite the absence of past vulnerabilities, the presence of unprotected AJAX endpoints remains the most pressing security concern. While the plugin has strengths in data handling and a clean history, the unprotected entry points introduce a substantial risk that needs immediate attention.
Key Concerns
- Unprotected AJAX handlers
- No capability checks on AJAX handlers
BP Activity Share Security Vulnerabilities
BP Activity Share Release Timeline
BP Activity Share Code Analysis
SQL Query Safety
Output Escaping
BP Activity Share Attack Surface
AJAX Handlers 2
WordPress Hooks 15
Maintenance & Trust
BP Activity Share Maintenance & Trust
Maintenance Signals
Community Trust
BP Activity Share Alternatives
BuddyPress Activity Shortcode
bp-activity-shortcode
BuddyPress Activity shortcode plugin allows you to insert BuddyPress activity stream on any page/post using shortcode.
Activity Plus Reloaded for BuddyPress
bp-activity-plus-reloaded
Note: This plugin will be discontinued by March 31st, 2025 in favor of BuddyPress Attachment plugin. Please migrate to the new plugin before that date …
BuddyPress Group Email Subscription
buddypress-group-email-subscription
This powerful plugin allows users to receive email notifications of group activity. Weekly or daily digests are available.
BuddyPress Edit Activity
buddypress-edit-activity
BuddyPress Edit Activity allows your members to edit their activity posts on the front-end of your BuddyPress-powered site.
Wbcom Designs – Shortcodes & Elementor Widgets For BuddyPress
shortcodes-for-buddypress
This plugin generates shortcodes for Listing Activity Streams, Members, and Groups on any website post or page.
BP Activity Share Developer Profile
4 plugins · 170 total installs
How We Detect BP Activity Share
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bp-activity-share/public/css/bp-activity-share-public.css/wp-content/plugins/bp-activity-share/public/js/bp-activity-share-public.js/wp-content/plugins/bp-activity-share/public/js/bp-activity-share-public.jsbp-activity-share/public/css/bp-activity-share-public.css?ver=bp-activity-share/public/js/bp-activity-share-public.js?ver=HTML / DOM Fingerprints
bp-activity-share-buttonbp-activity-share-custom-optionsdata-activity-iddata-bp-activity-share-noncebpShareActivity/wp-json/bp-activity-share/v1/share