
BP Group Documents Security & Risk Analysis
wordpress.org/plugins/bp-group-documentsBP Group Documents creates a page within each BuddyPress group to upload and any type of file or document.
Is BP Group Documents Safe to Use in 2026?
Generally Safe
Score 98/100BP Group Documents has a strong security track record. Known vulnerabilities have been patched promptly.
The bp-group-documents plugin v2.1 exhibits a mixed security posture. While static analysis indicates strong adherence to secure coding practices with a high percentage of properly escaped output, 100% of SQL queries using prepared statements, and robust nonce and capability checks on its single AJAX endpoint, there are concerning aspects. The presence of two taint flows with unsanitized paths, categorized as high severity, suggests a potential for path traversal vulnerabilities that could allow attackers to access or manipulate files outside of the intended directory. The plugin's historical vulnerability record, with four known CVEs including one high and three medium severity issues, further reinforces the need for caution. The types of past vulnerabilities, such as Path Traversal, CSRF, and XSS, align with the potential risks identified in the taint analysis. The last recorded vulnerability was in 2013, suggesting a lack of recent security attention, which can be a concern for a plugin with a history of security flaws.
Key Concerns
- High severity taint flows with unsanitized paths
- Historical high severity CVE
- Historical medium severity CVEs (3)
- Unsanitized paths in taint analysis
- File operations detected
BP Group Documents Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
BP Group Documents <= 1.2.1 - Path Traversal
BP Group Documents <= 1.2.1 - Cross-Site Request Forgery
BP Group Documents <= 1.2.1 - Stored Cross-Site Scripting
BP Group Documents <= 1.2 - Stored Cross-Site Scripting
BP Group Documents Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
BP Group Documents Attack Surface
AJAX Handlers 1
WordPress Hooks 35
Maintenance & Trust
BP Group Documents Maintenance & Trust
Maintenance Signals
Community Trust
BP Group Documents Alternatives
BP Profile Home Widgets
bp-profile-home-widgets
Add user editable widgets to the BP Nouveau profile home page with a widgets for text, video, posts, BuddyPress activity, mentions, friends and groups …
BP User Widgets
bp-user-widgets
Add user editable widgets to profile pages with a widgets for text, video, buddypress friends and groups, as well as followed and followiing.
BuddyPress User Info Widget
bp-profile-widget-for-blogs
BuddyPress User Info Widget allows easy listing of user profile info in the widget area.
Astra Widgets
astra-widgets
Quickest solution to add widgets like Address, Social Profiles and List icons on a website built with Astra.
Lightweight Social Icons
lightweight-social-icons
Looking to add simple social icons to your widget areas? Choose the size and color of your icons, and then choose from 47 different social profiles.
BP Group Documents Developer Profile
10 plugins · 2K total installs
How We Detect BP Group Documents
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bp-group-documents/assets/css/bp-group-documents.css/wp-content/plugins/bp-group-documents/assets/js/bp-group-documents.js/wp-content/plugins/bp-group-documents/assets/js/jquery.simpleUpload.js/wp-content/plugins/bp-group-documents/assets/js/bp-group-documents.js/wp-content/plugins/bp-group-documents/assets/js/jquery.simpleUpload.jsbp-group-documents/assets/css/bp-group-documents.css?ver=bp-group-documents/assets/js/bp-group-documents.js?ver=bp-group-documents/assets/js/jquery.simpleUpload.js?ver=HTML / DOM Fingerprints
bp-group-documents-upload-formbp-group-documents-file-listbp-group-documents-file-itembp-group-documents-actions<!-- BP Group Documents File Upload Form --><!-- BP Group Documents File List --><!-- BP Group Documents File Item -->data-group-iddata-user-iddata-file-idbp_group_documents_vars[bp_group_documents_upload_form][bp_group_documents_file_list]