BP Email to WP Mail From Bridge Security & Risk Analysis

wordpress.org/plugins/bp-email-to-wp-mail-from-bridge

>NOTE: As of BuddyPress 2.5.3+, this plugin is no longer needed.

10 active installs v1.1 PHP + WP 3.9+ Updated Jul 13, 2016
buddypressemail
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BP Email to WP Mail From Bridge Safe to Use in 2026?

Generally Safe

Score 85/100

BP Email to WP Mail From Bridge has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the bp-email-to-wp-mail-from-bridge plugin version 1.1 exhibits an exceptionally strong security posture. The code analysis reveals no identified attack surface entry points, no use of dangerous functions, and all SQL queries are properly prepared. Furthermore, all output is correctly escaped, and there are no file operations or external HTTP requests, significantly reducing potential exploitation vectors. The absence of any recorded vulnerabilities, including critical or high severity issues, further reinforces this positive assessment.

While the lack of nonce and capability checks is noted, it's important to consider this in conjunction with the zero attack surface. This suggests that the plugin may not have any direct interaction points that would necessitate these checks in its current version. The plugin's adherence to secure coding practices regarding SQL and output escaping is commendable. The absence of known vulnerabilities over its history implies a generally well-maintained and secure codebase.

In conclusion, the bp-email-to-wp-mail-from-bridge v1.1 appears to be a highly secure plugin. Its minimal attack surface, combined with robust secure coding practices and a clean vulnerability history, makes it a low-risk component. The absence of typical vulnerability indicators points to a well-developed and secure plugin. The only slight concern would be the lack of specific authorization checks, but this is mitigated by the fact that there are no discernible entry points where such checks would be immediately necessary in this version.

Key Concerns

  • No capability checks found
  • No nonce checks found
Vulnerabilities
None known

BP Email to WP Mail From Bridge Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

BP Email to WP Mail From Bridge Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

BP Email to WP Mail From Bridge Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionbp_emailbp-email-wp-mail-from-bridge.php:47
Maintenance & Trust

BP Email to WP Mail From Bridge Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedJul 13, 2016
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

BP Email to WP Mail From Bridge Developer Profile

Brandon Allen

5 plugins · 8K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BP Email to WP Mail From Bridge

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about BP Email to WP Mail From Bridge