
BP Distance Search Security & Risk Analysis
wordpress.org/plugins/bp-distance-searchAdds a Google Place Autocomplete profile field type for BuddyPress, and enables search by distance with BP Profile Search.
Is BP Distance Search Safe to Use in 2026?
Generally Safe
Score 100/100BP Distance Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bp-distance-search" v1.4.4 plugin exhibits a strong security posture based on the provided static analysis. The complete absence of entry points such as AJAX handlers, REST API routes, and shortcodes significantly limits its attack surface. Furthermore, all identified SQL queries are properly prepared, and there are no recorded file operations or external HTTP requests, which are common vectors for vulnerabilities. The lack of known CVEs and a clean vulnerability history also suggest a well-maintained and secure plugin.
However, there are areas that warrant attention. The most significant concern is the complete absence of nonce checks and capability checks. While the current attack surface is zero, any future additions to the plugin that introduce entry points without these fundamental security mechanisms could expose the site to cross-site request forgery (CSRF) and privilege escalation vulnerabilities. Additionally, a low percentage of properly escaped output (20%) indicates a potential for cross-site scripting (XSS) vulnerabilities, especially if any of the unsanitized outputs are triggered by user-controlled input that might be introduced in future updates.
In conclusion, the plugin is currently very secure due to its limited functionality and the absence of known vulnerabilities. However, the lack of essential security checks like nonces and capability checks, combined with poor output escaping, represents a latent risk that could materialize if the plugin's functionality or entry points expand without addressing these fundamental security practices. The developer should prioritize implementing these checks and improving output sanitization.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Low percentage of properly escaped output
BP Distance Search Security Vulnerabilities
BP Distance Search Release Timeline
BP Distance Search Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
BP Distance Search Attack Surface
WordPress Hooks 12
Maintenance & Trust
BP Distance Search Maintenance & Trust
Maintenance Signals
Community Trust
BP Distance Search Alternatives
BP Profile Search
bp-profile-search
Member search and member directories for BuddyPress and the BuddyBoss Platform.
GEO my WP
geo-my-wp
Advanced geolocation, mapping, and proximity search plugin. Geotag post types and BuddyPress members, and create advanced proximity search forms.
Eonet Live Search
eonet-live-search
Search dynamically in real time through all your site, including pages, posts, members, products & so on.
WP GeoPosts
wp-geoposts
A simple Wordpress plugin for adding geographic data to posts.
BP Members Avatar map
bp-members-avatar-map
Add a Google map display with all the members location with their avatar.
BP Distance Search Developer Profile
3 plugins · 7K total installs
How We Detect BP Distance Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bp-distance-search/bds-location.jshttps://maps.googleapis.com/maps/api/js?libraries=places&key=plugins_url('bp-distance-search/bds-location.js')HTML / DOM Fingerprints
dashiconsdashicons-locationid="field_.*_icon"id=".*_lat"id=".*_lng"name="Lat_field_.*"name="Lng_field_.*"aria-labelledby=".*-1"+2 morebds_autocompletebds_locate