BP Group Home Widgets Security & Risk Analysis

wordpress.org/plugins/bp-group-home-widgets

Adds admin editable widgets to the BP Nouveau group home page BP Legacy Home (Activity) pages with widgets for text, video, members, activity, comment …

10 active installs v1.1.0 PHP + WP + Updated Jul 21, 2024
bpbuddypressgroupnouveauwidget
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BP Group Home Widgets Safe to Use in 2026?

Generally Safe

Score 92/100

BP Group Home Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "bp-group-home-widgets" plugin version 1.1.0 exhibits a generally good security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history suggests a commitment to security by the developers. All AJAX handlers, the identified entry points, are protected by nonce checks, and capability checks are present in some instances. Furthermore, all SQL queries are using prepared statements, and there are no file operations or external HTTP requests, which are common vectors for vulnerabilities. The lack of bundled libraries also means the plugin isn't susceptible to vulnerabilities within outdated third-party code.

However, there are some areas for concern. The "Output escaping" metric shows that only 54% of outputs are properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities. While the "Taint Analysis" did not reveal critical or high severity unsanitized paths, the presence of 2 "flows with unsanitized paths" warrants further investigation to ensure these are indeed low risk. The overall attack surface, though protected, is comprised of 8 AJAX handlers, and a deeper dive into the implementation of these handlers is always recommended to ensure robust security, especially as only 3 out of 8 have explicit capability checks recorded.

Key Concerns

  • Only 54% of outputs properly escaped
  • 2 flows with unsanitized paths found
  • Capability checks on only 3 of 8 AJAX handlers
Vulnerabilities
None known

BP Group Home Widgets Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BP Group Home Widgets Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
62
73 escaped
Nonce Checks
8
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

54% escaped135 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

5 flows2 with unsanitized paths
bpghw_add_video (includes\bpghw-ajax.php:161)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

BP Group Home Widgets Attack Surface

Entry Points8
Unprotected0

AJAX Handlers 8

authwp_ajax_bpghw_moveable_widgetsincludes\bpghw-ajax.php:64
authwp_ajax_bpghw_reset_widgetincludes\bpghw-ajax.php:102
authwp_ajax_bpghw_clear_widgetincludes\bpghw-ajax.php:158
authwp_ajax_bpghw_add_videoincludes\bpghw-ajax.php:212
authwp_ajax_bpghw_add_textincludes\bpghw-ajax.php:265
authwp_ajax_bpghw_add_widgetincludes\bpghw-ajax.php:330
authwp_ajax_bpghw_clear_textincludes\bpghw-ajax.php:376
authwp_ajax_bpghw_update_presetsincludes\bpghw-ajax.php:436
WordPress Hooks 6
actionwp_enqueue_scriptsbp-group-home-widgets.php:91
actioninitbp-group-home-widgets.php:100
actionwidgets_initbp-group-home-widgets.php:122
actionwidgets_initincludes\bpghw-functions.php:558
actionbp_after_group_activity_contentincludes\bpghw-functions.php:581
actionbp_before_group_activity_contentincludes\bpghw-functions.php:582
Maintenance & Trust

BP Group Home Widgets Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedJul 21, 2024
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

BP Group Home Widgets Developer Profile

Venutius

20 plugins · 640 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BP Group Home Widgets

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bp-group-home-widgets/js/bpghw-group-widgets-front-end.js/wp-content/plugins/bp-group-home-widgets/vendor/jquery/jquery-ui.css/wp-content/plugins/bp-group-home-widgets/css/bpghw.css
Script Paths
/wp-content/plugins/bp-group-home-widgets/js/bpghw-group-widgets-front-end.js
Version Parameters
bpghw-group-widgets-front-end.js?ver=jquery-ui.css?ver=bpghw.css?ver=

HTML / DOM Fingerprints

Data Attributes
data-widget-iddata-widget-typedata-widget-name
JS Globals
bpghw_translateajax_object
FAQ

Frequently Asked Questions about BP Group Home Widgets