BP Blog Author Link Security & Risk Analysis

wordpress.org/plugins/bp-blog-author-link

This plugin changes the blog author links on a buddypress site to link to the author's buddypress member profile.

50 active installs v2.8.1 PHP + WP 3.0+ Updated Jun 29, 2014
authorbuddypresswpmu
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BP Blog Author Link Safe to Use in 2026?

Generally Safe

Score 85/100

BP Blog Author Link has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The static analysis of the 'bp-blog-author-link' plugin version 2.8.1 reveals a strong security posture. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code signals indicate excellent security practices, with no dangerous functions, all SQL queries using prepared statements, and all output properly escaped. The lack of file operations, external HTTP requests, nonce checks, and capability checks, while seemingly a positive, also indicates a very limited scope of functionality where these might be applicable.

The taint analysis found no unsanitized paths, which is a positive sign for data handling. The vulnerability history is also clean, with no recorded CVEs. This plugin demonstrates a commendable adherence to secure coding principles within its analyzed functionality. However, the very limited attack surface and lack of certain security checks (like nonces and capability checks) might suggest that the plugin performs very basic or no dynamic operations that would typically necessitate these.

In conclusion, 'bp-blog-author-link' v2.8.1 appears to be a very secure plugin based on this analysis. Its strengths lie in its minimal attack surface and the evident use of secure coding practices like prepared statements and output escaping. The absence of any reported vulnerabilities further bolsters its security. The main observation is the limited functionality that prevents a more comprehensive assessment of certain security controls, but within its scope, it is well-protected.

Vulnerabilities
None known

BP Blog Author Link Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BP Blog Author Link Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

BP Blog Author Link Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterauthor_linkra-bp-author-link.php:29
actionwp_headra-bp-author-link.php:31
Maintenance & Trust

BP Blog Author Link Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedJun 29, 2014
PHP min version
Downloads9K

Community Trust

Rating100/100
Number of ratings6
Active installs50
Developer Profile

BP Blog Author Link Developer Profile

Ron Rennick

10 plugins · 1K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BP Blog Author Link

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about BP Blog Author Link