
Wbcom Designs – BuddyPress Activity Social Share Security & Risk Analysis
wordpress.org/plugins/bp-activity-social-shareA free WordPress plugin enables easy sharing of BuddyPress activities across major social media platforms such as Facebook, Twitter, and LinkedIn.
Is Wbcom Designs – BuddyPress Activity Social Share Safe to Use in 2026?
Generally Safe
Score 91/100Wbcom Designs – BuddyPress Activity Social Share has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "bp-activity-social-share" plugin v3.5.4 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries and achieving a high percentage (90%) of properly escaped outputs. It also includes nonce checks and capability checks on a significant portion of its entry points, and importantly, there are no known unpatched vulnerabilities at this time. The taint analysis also shows no critical or high-severity issues with unsanitized paths.
However, there are notable concerns. The plugin has a substantial attack surface consisting of 6 entry points, with 4 of these (a significant majority) lacking authentication checks. This lack of authorization on multiple AJAX handlers is a critical weakness, potentially allowing unauthorized users to trigger plugin functionalities. Furthermore, the plugin has a history of 2 medium-severity vulnerabilities, primarily related to Cross-Site Request Forgery (CSRF) and Missing Authorization. While currently unpatched vulnerabilities are zero, this historical pattern suggests a recurring tendency towards authorization and input validation flaws.
In conclusion, while the plugin has made strides in secure coding practices like prepared SQL and output escaping, the presence of numerous unprotected AJAX handlers is a serious security risk that requires immediate attention. The historical vulnerability pattern reinforces this concern. The plugin is moderately secure, but the extensive unprotected entry points significantly detract from its overall security.
Key Concerns
- AJAX handlers without auth checks
- History of medium severity vulnerabilities
Wbcom Designs – BuddyPress Activity Social Share Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Wbcom Designs – BuddyPress Activity Social Share <= 3.5.0 - Cross-Site Request Forgery
Wbcom Designs Plugins (Various Versions) - Arbitrary Plugin Installation, Activation and Deactivation
Wbcom Designs – BuddyPress Activity Social Share Release Timeline
Wbcom Designs – BuddyPress Activity Social Share Code Analysis
Output Escaping
Data Flow Analysis
Wbcom Designs – BuddyPress Activity Social Share Attack Surface
AJAX Handlers 5
Shortcodes 1
WordPress Hooks 27
Maintenance & Trust
Wbcom Designs – BuddyPress Activity Social Share Maintenance & Trust
Maintenance Signals
Community Trust
Wbcom Designs – BuddyPress Activity Social Share Alternatives
Re-post Activity for BuddyPress
bp-repost-activity
Re-Post an Activity from activity stream. Re-post an activity to your group and personal activity.
BP Activity Share
bp-activity-share
Using BP Activity Share plugin you can share any activity locally like we share any post in FaceBook.
BuddyPress Activity Shortcode
bp-activity-shortcode
BuddyPress Activity shortcode plugin allows you to insert BuddyPress activity stream on any page/post using shortcode.
Activity Plus Reloaded for BuddyPress
bp-activity-plus-reloaded
Note: This plugin will be discontinued by March 31st, 2025 in favor of BuddyPress Attachment plugin. Please migrate to the new plugin before that date …
BuddyPress Group Email Subscription
buddypress-group-email-subscription
This powerful plugin allows users to receive email notifications of group activity. Weekly or daily digests are available.
Wbcom Designs – BuddyPress Activity Social Share Developer Profile
19 plugins · 10K total installs
How We Detect Wbcom Designs – BuddyPress Activity Social Share
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bp-activity-social-share/css/style.css/wp-content/plugins/bp-activity-social-share/js/bp-share.js/wp-content/plugins/bp-activity-social-share/js/social-sharing.js/wp-content/plugins/bp-activity-social-share/js/bp-share.js/wp-content/plugins/bp-activity-social-share/js/social-sharing.jsbp-activity-social-share/css/style.css?ver=bp-activity-social-share/js/bp-share.js?ver=bp-activity-social-share/js/social-sharing.js?ver=HTML / DOM Fingerprints
bp-share-social-share-buttonbp-share-button-wrapperdata-bp-share-post-iddata-bp-share-post-urlbpShare