
BP Disable Activation Reloaded Security & Risk Analysis
wordpress.org/plugins/bp-disable-activation-reloadedBased on crashutah, apeatling plugin Disables the activation email and automatically activates new users in BuddyPress under a standard WP install and …
Is BP Disable Activation Reloaded Safe to Use in 2026?
Use With Caution
Score 63/100BP Disable Activation Reloaded has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "bp-disable-activation-reloaded" plugin version 1.2.1 exhibits a mixed security posture. On the positive side, the static analysis shows a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are accessible without authentication or proper permission checks. Furthermore, the code doesn't appear to utilize dangerous functions, perform file operations, make external HTTP requests, or bundle external libraries, which are generally good practices.
However, there are significant concerns, particularly regarding output escaping and SQL query security. A concerning 82% of output is not properly escaped, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. While SQL queries are used, only 50% are prepared, leaving potential for SQL injection if the other 50% are handling user-supplied data unsafely. The lack of any nonce or capability checks across the board is also a significant weakness, especially when combined with the output escaping issues.
The plugin's vulnerability history is a major red flag. With one known medium-severity CVE that is currently unpatched, and a pattern of previous CSRF vulnerabilities, it indicates a history of security flaws that have not been fully addressed. This suggests a potential lack of robust security testing or developer attention to security best practices. The unpatched CVE is the most immediate and critical concern, as it represents a known exploit that could be leveraged against users of this plugin.
Key Concerns
- Unpatched Medium CVE
- High percentage of unescaped output (82%)
- 50% of SQL queries not using prepared statements
- 0 Nonce checks
- 0 Capability checks
BP Disable Activation Reloaded Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
BP Disable Activation Reloaded <= 1.2.1 - Cross-Site Request Forgery
BP Disable Activation Reloaded Code Analysis
SQL Query Safety
Output Escaping
BP Disable Activation Reloaded Attack Surface
WordPress Hooks 10
Maintenance & Trust
BP Disable Activation Reloaded Maintenance & Trust
Maintenance Signals
Community Trust
BP Disable Activation Reloaded Alternatives
BP Disable Activation
bp-disable-activation
Disables the activation email and automatically activates new users in BuddyPress under a standard WP install and WPMU (multisite).
BuddyPress Russian Months
buddypress-russian-months
Plugin will transform wrong months' cases (in date) to proper ones (according Russian grammar rules).
Demo Data Creator
demo-data-creator
Demo Data Creator is a Wordpress and BuddyPress plugin that allows a Wordpress developer to create demo users, blogs, posts, comments and more.
Vibe BuddyPress Mails via WPMail
vibe-buddypress-to-wp-mail-fix
Send BuddyPress HTML Emails via WordPress Mail system.
BP Blog Author Link
bp-blog-author-link
This plugin changes the blog author links on a buddypress site to link to the author's buddypress member profile.
BP Disable Activation Reloaded Developer Profile
6 plugins · 34K total installs
How We Detect BP Disable Activation Reloaded
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bp-disable-activation-reloaded/css/bp-disable-activation-reloaded.css/wp-content/plugins/bp-disable-activation-reloaded/js/bp-disable-activation-reloaded.js/wp-content/plugins/bp-disable-activation-reloaded/js/bp-disable-activation-reloaded.jsbp-disable-activation-reloaded/css/bp-disable-activation-reloaded.css?ver=bp-disable-activation-reloaded/js/bp-disable-activation-reloaded.js?ver=HTML / DOM Fingerprints
<!-- BP Disable Activation Reloaded -->