BP Group Hierarchy Propagate Security & Risk Analysis

wordpress.org/plugins/bp-group-hierarchy-propagate

Enables propagation of Activity Items through a hierarchy of BuddyPress Groups established by the BP Group Hierarchy plugin.

10 active installs v0.3.3 PHP + WP 3.5+ Updated Apr 5, 2016
activitybuddypressgroupshierarchypropagate
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BP Group Hierarchy Propagate Safe to Use in 2026?

Generally Safe

Score 85/100

BP Group Hierarchy Propagate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "bp-group-hierarchy-propagate" plugin, version 0.3.3, exhibits a generally strong security posture based on the provided static analysis. The absence of any detected dangerous functions, SQL queries executed without prepared statements, and the consistent use of output escaping are all positive indicators. Furthermore, the plugin has no recorded vulnerabilities (CVEs), which suggests a history of responsible development and maintenance or a lack of prior discovery. The extremely small attack surface, with zero identified entry points and zero critical or high severity taint flows, further reinforces a low-risk profile.

However, a notable concern arises from the complete lack of any capability checks or nonce checks identified in the analysis. While the current attack surface is minimal, this absence of core WordPress security mechanisms means that if any new entry points were introduced or discovered in the future, they would likely be unprotected. This presents a potential vulnerability for future exploitation if the plugin evolves or is integrated into more complex scenarios without incorporating these essential security checks. The lack of any logged vulnerabilities is a positive trend, but it should not be seen as a guarantee against future issues, especially given the observed gaps in fundamental security implementations.

Key Concerns

  • Missing capability checks
  • Missing nonce checks
Vulnerabilities
None known

BP Group Hierarchy Propagate Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

BP Group Hierarchy Propagate Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

BP Group Hierarchy Propagate Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedbp-group-hierarchy-propagate.php:65
actionbpgh_admin_after_settingsbp-group-hierarchy-propagate.php:68
actionbpgh_admin_after_savebp-group-hierarchy-propagate.php:71
filterbp_has_activitiesbp-group-hierarchy-propagate.php:80
filterbp_has_activitiesbp-group-hierarchy-propagate.php:85
filterbp_has_activitiesbp-group-hierarchy-propagate.php:90
actionbp_setup_globalsbp-group-hierarchy-propagate.php:467
Maintenance & Trust

BP Group Hierarchy Propagate Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedApr 5, 2016
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

BP Group Hierarchy Propagate Developer Profile

Christian Wach

8 plugins · 2K total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BP Group Hierarchy Propagate

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
/bp-group-hierarchy-propagate/bp-group-hierarchy-propagate.php?ver=bp-group-hierarchy-propagate/bp-group-hierarchy-propagate.php?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about BP Group Hierarchy Propagate