
BP Expand Activity Security & Risk Analysis
wordpress.org/plugins/bp-expand-activityAdds AJAX capabilities to expand shortened activity stream wire comments without reloading the page.
Is BP Expand Activity Safe to Use in 2026?
Generally Safe
Score 85/100BP Expand Activity has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'bp-expand-activity' plugin version 1.0 exhibits a generally positive security posture due to the absence of known vulnerabilities and critical code signals. The static analysis indicates a small attack surface, with only one AJAX handler, and importantly, no REST API routes or shortcodes exposed. The plugin also correctly utilizes prepared statements for all SQL queries, a crucial security practice. However, a significant concern arises from the complete lack of output escaping, meaning any data displayed to users is not being sanitized, potentially opening the door for cross-site scripting (XSS) attacks. Additionally, while a nonce check is present for the AJAX handler, capability checks are entirely absent, leaving the AJAX endpoint vulnerable to unauthorized access if an attacker can trigger it.
Key Concerns
- Missing capability checks on AJAX handler
- No output escaping on any outputs
BP Expand Activity Security Vulnerabilities
BP Expand Activity Release Timeline
BP Expand Activity Code Analysis
Output Escaping
BP Expand Activity Attack Surface
AJAX Handlers 1
WordPress Hooks 3
Maintenance & Trust
BP Expand Activity Maintenance & Trust
Maintenance Signals
Community Trust
BP Expand Activity Alternatives
Activity Plus Reloaded for BuddyPress
bp-activity-plus-reloaded
Note: This plugin will be discontinued by March 31st, 2025 in favor of BuddyPress Attachment plugin. Please migrate to the new plugin before that date …
BuddyKit – Additional features for BuddyPress
buddykit
BuddyKit adds several features like Live Notifications and Media Activities to your BuddyPress powered websites.
BuddyPress Edit Activity Stream
buddypress-edit-activity-stream
This plugin allows an user to edit their activity stream status update within a specified time period.
Buddypress Activity Plus Styling
bp-activity-plus-styling
Additional CSS styles for the Buddypress Activity Plus plugin.
BuddyPress Activity Stream Bump to Top
buddypress-activity-stream-bump-to-top
This plugin will "bump" an activity record to the top of the stream when activity comment reply is made.
BP Expand Activity Developer Profile
13 plugins · 176K total installs
How We Detect BP Expand Activity
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bp-expand-activity/bp-expand-activity/ajax.js/bp-expand-activity/bp-expand-activity/ajax.jsHTML / DOM Fingerprints
bp-expand-activityid="bp-expand-activity-rel="profile/new_wire_post/