BP Emails for BBP Security & Risk Analysis

wordpress.org/plugins/bp-emails-for-bbp

Send bbPress forum and topic subscription emails using Buddypress' email API.

20 active installs v0.2.3 PHP 5.2.4+ WP 4.2.0+ Updated Jan 15, 2018
bbpressbuddypressemail
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BP Emails for BBP Safe to Use in 2026?

Generally Safe

Score 85/100

BP Emails for BBP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "bp-emails-for-bbp" plugin v0.2.3 demonstrates a generally strong security posture based on the static analysis. The plugin exhibits excellent practices by having zero identified dangerous functions, all SQL queries utilizing prepared statements, and all output being properly escaped. Furthermore, the absence of file operations and critical/high severity taint flows indicates a low risk of common code injection and data manipulation vulnerabilities. The plugin also has no recorded vulnerabilities, which is a positive indicator of its historical security.

However, there are a few areas that warrant attention. The plugin's attack surface is zero, which is ideal. The lack of nonce checks, despite having a capability check, could be a concern if any of the entry points were to be exposed or become exploitable in the future. The presence of an external HTTP request, while not inherently dangerous, is a potential vector for issues if not handled with extreme care regarding data validation and sanitization on both ends. The fact that no taint flows were analyzed or found could indicate a very small codebase or limitations in the analysis tool itself, rather than absolute safety.

In conclusion, the plugin appears to be well-coded with good security fundamentals. The primary weaknesses lie in the potential, albeit currently unrealized, risks associated with the external HTTP request and the absence of nonce checks on its limited entry points. The lack of historical vulnerabilities is a significant strength. While the current risk appears low, continuous vigilance and potentially more comprehensive taint analysis in the future would be beneficial.

Key Concerns

  • No nonce checks detected
  • External HTTP request present
Vulnerabilities
None known

BP Emails for BBP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BP Emails for BBP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
13 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped13 total outputs
Attack Surface

BP Emails for BBP Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_noticesbp-emails-for-bbp.php:47
actionplugins_loadedbp-emails-for-bbp.php:60
actionwp_async_bbp_new_topicclasses\class-bp-emails-for-bbp.php:81
actionwp_async_bbp_new_replyclasses\class-bp-emails-for-bbp.php:87
filterbp_email_get_propertyclasses\class-bp-emails-for-bbp.php:90
actionadmin_initclasses\class-bpebbp-admin.php:71
actionbp_core_install_emailsclasses\class-bpebbp-admin.php:74
actionshutdownclasses\class-wp-async-task.php:112
filterwp_die_handlerclasses\class-wp-async-task.php:170
Maintenance & Trust

BP Emails for BBP Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 15, 2018
PHP min version5.2.4
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs20
Developer Profile

BP Emails for BBP Developer Profile

Brandon Allen

5 plugins · 8K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BP Emails for BBP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bp-emails-for-bbp/css/bp-emails-for-bbp.css/wp-content/plugins/bp-emails-for-bbp/js/bp-emails-for-bbp.js
Script Paths
/wp-content/plugins/bp-emails-for-bbp/js/bp-emails-for-bbp.js
Version Parameters
bp-emails-for-bbp/css/bp-emails-for-bbp.css?ver=bp-emails-for-bbp/js/bp-emails-for-bbp.js?ver=

HTML / DOM Fingerprints

JS Globals
BP_Emails_For_BBP
FAQ

Frequently Asked Questions about BP Emails for BBP