
BP Custom Pages Security & Risk Analysis
wordpress.org/plugins/bp-custom-pagesThis is a BuddyPress plugin which allows site admins to create up to 4 "Custom Pages" which are displayed automatically in the users "C …
Is BP Custom Pages Safe to Use in 2026?
Generally Safe
Score 92/100BP Custom Pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The bp-custom-pages v1.2.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history are positive indicators. The code demonstrates good practices by utilizing prepared statements for all SQL queries, performing a reasonable number of output escapes, and incorporating nonce and capability checks, suggesting an awareness of common WordPress security pitfalls.
However, the taint analysis reveals two flows with unsanitized paths, classified as high severity. While the plugin has a limited attack surface and no direct evidence of exploitable vulnerabilities from the static analysis alone, these unsanitized paths represent a potential risk. Without further context on these specific flows, it's difficult to definitively assess their exploitability, but they warrant attention as they indicate areas where user-supplied data might not be adequately validated or neutralized before being used in sensitive operations, potentially leading to unexpected behavior or information disclosure.
In conclusion, while the plugin is not actively known to be vulnerable and incorporates several security best practices, the identified high-severity taint flows introduce a notable concern. The absence of a larger attack surface and historical vulnerabilities is a significant strength, but these specific code-level issues require further investigation to ensure they do not pose a tangible security threat. The overall security is good, but with a potential for improvement in input sanitization.
Key Concerns
- High severity taint flow with unsanitized path
- High severity taint flow with unsanitized path
- Minor output escaping concern (8% unescaped)
BP Custom Pages Security Vulnerabilities
BP Custom Pages Release Timeline
BP Custom Pages Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
BP Custom Pages Attack Surface
WordPress Hooks 13
Maintenance & Trust
BP Custom Pages Maintenance & Trust
Maintenance Signals
Community Trust
BP Custom Pages Alternatives
BuddyForms Moderation ( Former: Review Logic )
buddyforms-review
Create new drafts or pending reviews from new or published posts without changing the live version.
FrontPage Buddy – Custom landing pages for members, groups and profiles
frontpage-buddy
Personalised front pages for buddypress & buddyboss members & groups, bbpress profiles and 'Ultimate Member' profiles.
BuddyForms Form Elements for WooCommerce
buddyforms-woocommerce-form-elements
Let your WooCommerce Vendors Manage there Products from the Frontend
BuddyForms Simple Auctions Integration for WooCommerce
buddyforms-woocommerce-simple-auction
Add the WooCommerce Simple Auction Form Elements to BuddyForms
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress
youzify
The best BuddyPress plugin for building online communities, user profile, social networks, and membership sites on WordPress with tons of features.
BP Custom Pages Developer Profile
21 plugins · 650 total installs
How We Detect BP Custom Pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bp-custom-pages/css/bp-custom-pages.css/wp-content/plugins/bp-custom-pages/js/bp-custom-pages.js/wp-content/plugins/bp-custom-pages/js/bp-custom-pages-admin.js/wp-content/plugins/bp-custom-pages/js/bp-custom-pages.js/wp-content/plugins/bp-custom-pages/js/bp-custom-pages-admin.jsbp-custom-pages/css/bp-custom-pages.css?ver=bp-custom-pages/js/bp-custom-pages.js?ver=bp-custom-pages/js/bp-custom-pages-admin.js?ver=HTML / DOM Fingerprints
<!-- BP Custom Pages Plugin --><!-- BP Custom Pages Admin Plugin -->bp_custom_pages_params