BuddyPress Featured Members Security & Risk Analysis

wordpress.org/plugins/bp-featured-members

BuddyPress Featured Members plugin allows site admins to mark users as featured and display their list.

400 active installs v1.1.5 PHP + WP 4.5.0+ Updated Jun 16, 2025
buddypressfeatured-members
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BuddyPress Featured Members Safe to Use in 2026?

Generally Safe

Score 100/100

BuddyPress Featured Members has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "bp-featured-members" v1.1.5 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of critical taint flows, dangerous functions, raw SQL queries, and external HTTP requests are significant strengths. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and including a nonce check on its single AJAX handler. The lack of known vulnerabilities in its history is also a positive indicator of its maintenance and security awareness.

However, a notable concern arises from the output escaping. With 93 outputs analyzed, only 59% are properly escaped. This leaves a significant portion of the plugin's output potentially vulnerable to cross-site scripting (XSS) attacks if user-supplied data is directly incorporated into these unescaped outputs. While the plugin has no recorded vulnerability history, this high percentage of unescaped output represents a tangible risk that should be addressed.

In conclusion, "bp-featured-members" v1.1.5 is strong in many foundational security areas. The absence of severe code-level vulnerabilities and a clean vulnerability history are commendable. The primary weakness lies in the insufficient output escaping, which presents a moderate risk. Addressing this specific area would significantly enhance the plugin's overall security.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

BuddyPress Featured Members Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

BuddyPress Featured Members Release Timeline

v1.1.5Current
v1.1.4
v1.1.3
v1.1.2
v1.1.1
v1.1.0
v1.0.9
v1.0.8
v1.0.7
v1.0.6
v1.0.5
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

BuddyPress Featured Members Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
38
55 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

59% escaped93 total outputs
Attack Surface

BuddyPress Featured Members Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_bp_process_featured_members_statuscore\class-bp-featured-members-ajax-handler.php:16

Shortcodes 1

[bp-featured-members] core\bp-featured-members-shortcode.php:13
WordPress Hooks 10
actionbp_loadedbp-featured-members.php:86
actionbp_initbp-featured-members.php:87
actionbp_enqueue_scriptsbp-featured-members.php:89
actionadmin_print_scripts-widgets.phpbp-featured-members.php:91
filterbp_after_has_members_parse_argscore\bp-featured-members-filters.php:49
actionbp_widgets_initcore\class-bp-featured-members-widget.php:335
actionbp_directory_members_actionscore\class-featured-members-template-helper.php:18
actionbp_group_members_list_item_actioncore\class-featured-members-template-helper.php:19
actionbp_member_header_actionscore\class-featured-members-template-helper.php:20
actionbp_members_directory_member_typescore\class-featured-members-template-helper.php:22
Maintenance & Trust

BuddyPress Featured Members Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 16, 2025
PHP min version
Downloads28K

Community Trust

Rating94/100
Number of ratings3
Active installs400
Developer Profile

BuddyPress Featured Members Developer Profile

BuddyDev

15 plugins · 15K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
17 days
View full developer profile
Detection Fingerprints

How We Detect BuddyPress Featured Members

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bp-featured-members/assets/css/lightslider.min.css/wp-content/plugins/bp-featured-members/assets/js/lightslider.min.js/wp-content/plugins/bp-featured-members/assets/js/bp-featured-members.js/wp-content/plugins/bp-featured-members/assets/js/bp-featured-members-admin.js
Script Paths
assets/js/bp-featured-members.jsassets/js/bp-featured-members-admin.jsassets/js/lightslider.min.js
Version Parameters
bp-featured-members/assets/js/bp-featured-members.js?ver=bp-featured-members/assets/js/bp-featured-members-admin.js?ver=bp-featured-members/assets/css/lightslider.min.css?ver=bp-featured-members/assets/js/lightslider.min.js?ver=

HTML / DOM Fingerprints

JS Globals
bp_featured_members
Shortcode Output
[bp-featured-members]
FAQ

Frequently Asked Questions about BuddyPress Featured Members