
BuddyPress Automatic Friends Security & Risk Analysis
wordpress.org/plugins/bp-automatic-friendsAutomatically create and accept friendships for specified users upon new user registration. * Requires BuddyPress
Is BuddyPress Automatic Friends Safe to Use in 2026?
Generally Safe
Score 85/100BuddyPress Automatic Friends has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bp-automatic-friends" plugin v2.0.8 exhibits a generally good security posture with a small attack surface consisting solely of AJAX handlers. Encouragingly, none of these AJAX handlers are exposed without authentication, and the plugin demonstrates robust SQL query sanitization through the consistent use of prepared statements. The absence of any recorded vulnerabilities, including CVEs, further strengthens its current security standing. However, a significant concern arises from the complete lack of output escaping for all 13 identified output points. This oversight creates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as untrusted data could be rendered directly in the browser, potentially allowing attackers to inject malicious scripts. While the plugin has no known historical vulnerabilities, the identified output escaping issue is a critical weakness that requires immediate attention.
Key Concerns
- Output escaping is not properly implemented
BuddyPress Automatic Friends Security Vulnerabilities
BuddyPress Automatic Friends Code Analysis
SQL Query Safety
Output Escaping
BuddyPress Automatic Friends Attack Surface
AJAX Handlers 3
WordPress Hooks 10
Maintenance & Trust
BuddyPress Automatic Friends Maintenance & Trust
Maintenance Signals
Community Trust
BuddyPress Automatic Friends Alternatives
aapanel WP Toolkit
aapanel-wp-toolkit
A better way to manage dozens of WordPress websites.
Registration Options for BuddyPress
bp-registration-options
Moderate new BuddyPress members and fight BuddyPress spam.
Invite Anyone
invite-anyone
Makes BuddyPress's invitation features more powerful.
WP Updates Settings
wp-updates-settings
Configure WordPress updates settings through UI (User Interface).
WP Login Timeout Settings
wp-login-timeout-settings
Configure WordPress Login Timeout through UI (User Interface).
BuddyPress Automatic Friends Developer Profile
2 plugins · 210 total installs
How We Detect BuddyPress Automatic Friends
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bp-automatic-friends/css/bpaf-admin-styles.css/wp-content/plugins/bp-automatic-friends/js/bpaf-admin-scripts.js/wp-content/plugins/bp-automatic-friends/js/bpaf-admin-scripts.jsbp-automatic-friends/css/bpaf-admin-styles.css?ver=bp-automatic-friends/js/bpaf-admin-scripts.js?ver=HTML / DOM Fingerprints
bpaf-settings-fieldbpaf-global-friends-wrapperbpaf-user-search-wrap<!-- BuddyPress Automatic Friends Core --><!-- Core plugin class --><!-- Load the admin --><!-- Do this the first time a new user logs in -->+22 moredata-bpaf-actiondata-bpaf-user-iddata-bpaf-noncedata-bpaf-target-user-idbpaf_global_vars