BP Blacklist Signup by Email Domain Security & Risk Analysis

wordpress.org/plugins/bp-blacklist-signup-by-email-domain

Only allow users with email addresses not on the domain blacklist to register in BuddyPress.

10 active installs v1.1.0 PHP + WP + Updated Jul 20, 2024
buddypressemail-blacklistregistration
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BP Blacklist Signup by Email Domain Safe to Use in 2026?

Generally Safe

Score 92/100

BP Blacklist Signup by Email Domain has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "bp-blacklist-signup-by-email-domain" v1.1.0 exhibits a strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. The code further demonstrates good practices by exclusively using prepared statements for SQL queries, having a high percentage of properly escaped output, and including a nonce check. The lack of file operations and external HTTP requests further reduces potential vectors for compromise. Moreover, the plugin has no recorded vulnerabilities (CVEs), indicating a history of secure development or diligent patching by its maintainers.

Despite the overall positive assessment, the primary area for potential concern lies in the absence of capability checks. While the limited attack surface currently mitigates this risk, any future addition of features that could be exploited by unauthenticated users might become a security concern if capability checks are not implemented. The taint analysis showing zero flows with unsanitized paths is a very positive indicator of secure coding, but it's important to remember that static analysis is not exhaustive. In conclusion, this plugin appears to be very secure, with its strengths lying in its minimal attack surface and adherence to secure coding practices. The absence of capability checks is a minor point of observation rather than a direct, present risk, given the current code.

Vulnerabilities
None known

BP Blacklist Signup by Email Domain Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BP Blacklist Signup by Email Domain Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
8 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

89% escaped9 total outputs
Attack Surface

BP Blacklist Signup by Email Domain Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionbp_includebp-blacklist-signup-by-email-domain.php:21
actionbp_signup_validatebp-blacklist-signup-by-email-domain.php:51
actionbp_before_account_details_fieldsbp-blacklist-signup-by-email-domain.php:52
actionbp_admin_initbp-bsed-admin.php:34
actionbp_register_admin_settingsbp-bsed-admin.php:35
Maintenance & Trust

BP Blacklist Signup by Email Domain Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedJul 20, 2024
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

BP Blacklist Signup by Email Domain Developer Profile

Venutius

20 plugins · 640 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BP Blacklist Signup by Email Domain

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about BP Blacklist Signup by Email Domain