
BP Group Hierarchy Propagate Security & Risk Analysis
wordpress.org/plugins/bp-group-hierarchy-propagateEnables propagation of Activity Items through a hierarchy of BuddyPress Groups established by the BP Group Hierarchy plugin.
Is BP Group Hierarchy Propagate Safe to Use in 2026?
Generally Safe
Score 85/100BP Group Hierarchy Propagate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bp-group-hierarchy-propagate" plugin, version 0.3.3, exhibits a generally strong security posture based on the provided static analysis. The absence of any detected dangerous functions, SQL queries executed without prepared statements, and the consistent use of output escaping are all positive indicators. Furthermore, the plugin has no recorded vulnerabilities (CVEs), which suggests a history of responsible development and maintenance or a lack of prior discovery. The extremely small attack surface, with zero identified entry points and zero critical or high severity taint flows, further reinforces a low-risk profile.
However, a notable concern arises from the complete lack of any capability checks or nonce checks identified in the analysis. While the current attack surface is minimal, this absence of core WordPress security mechanisms means that if any new entry points were introduced or discovered in the future, they would likely be unprotected. This presents a potential vulnerability for future exploitation if the plugin evolves or is integrated into more complex scenarios without incorporating these essential security checks. The lack of any logged vulnerabilities is a positive trend, but it should not be seen as a guarantee against future issues, especially given the observed gaps in fundamental security implementations.
Key Concerns
- Missing capability checks
- Missing nonce checks
BP Group Hierarchy Propagate Security Vulnerabilities
BP Group Hierarchy Propagate Code Analysis
BP Group Hierarchy Propagate Attack Surface
WordPress Hooks 7
Maintenance & Trust
BP Group Hierarchy Propagate Maintenance & Trust
Maintenance Signals
Community Trust
BP Group Hierarchy Propagate Alternatives
BuddyPress Group Email Subscription
buddypress-group-email-subscription
This powerful plugin allows users to receive email notifications of group activity. Weekly or daily digests are available.
Wbcom Designs – Shortcodes & Elementor Widgets For BuddyPress
shortcodes-for-buddypress
This plugin generates shortcodes for Listing Activity Streams, Members, and Groups on any website post or page.
Buddypress Avatar Hover
bp-avatar-hover
BuddyPress Avatar Hover let's you add a pop box when hovering on the group/member avatars and gives you more information at a glance.
BuddyPress Activity Stream AtGroups
buddypress-activity-stream-atgroups
This plugin will link @(group_slug) syntax to group home page and/or use =(group_slug) to post an update to group
BuddyPress Activity Shortcode
bp-activity-shortcode
BuddyPress Activity shortcode plugin allows you to insert BuddyPress activity stream on any page/post using shortcode.
BP Group Hierarchy Propagate Developer Profile
8 plugins · 2K total installs
How We Detect BP Group Hierarchy Propagate
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/bp-group-hierarchy-propagate/bp-group-hierarchy-propagate.php?ver=bp-group-hierarchy-propagate/bp-group-hierarchy-propagate.php?ver=