
BP Custom Functionalities Security & Risk Analysis
wordpress.org/plugins/bp-custom-functionalitiesBP Custom Functionalities provides custom functionalities that regular BuddyPress users requires.
Is BP Custom Functionalities Safe to Use in 2026?
Generally Safe
Score 92/100BP Custom Functionalities has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bp-custom-functionalities" plugin version 1.0.4 demonstrates a generally strong security posture based on the provided static analysis. The absence of any known vulnerabilities in its history and the limited attack surface are positive indicators. The code analysis reveals a commitment to secure coding practices, with no dangerous functions, no unescaped external HTTP requests, and all SQL queries utilizing prepared statements. The presence of nonce and capability checks further bolsters its security. However, a significant concern arises from the output escaping. With 8 total outputs and only 25% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts through these unescaped outputs, leading to session hijacking or other client-side attacks. While the taint analysis found no unsanitized paths, the high percentage of unescaped output is a critical weakness that needs immediate attention. The plugin's vulnerability history is clean, which is reassuring, but the static analysis flags a clear and present danger in how it handles output.
Key Concerns
- High percentage of unescaped output
BP Custom Functionalities Security Vulnerabilities
BP Custom Functionalities Code Analysis
Output Escaping
Data Flow Analysis
BP Custom Functionalities Attack Surface
WordPress Hooks 9
Maintenance & Trust
BP Custom Functionalities Maintenance & Trust
Maintenance Signals
Community Trust
BP Custom Functionalities Alternatives
BP Custom Functionalities Developer Profile
2 plugins · 310 total installs
How We Detect BP Custom Functionalities
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapform-tablename="ps_lock_bp"name="ps_exclude_levels[]"name="ps_exclude_roles[]"name="save_ps_settings"name="bp_cfunc_settings"