
BuddyPress Elevator Pitch – Enhanced Member Cards Security & Risk Analysis
wordpress.org/plugins/bp-group-members-dataChoose which fields appear on the "member cards" on member list pages, such as Groups.
Is BuddyPress Elevator Pitch – Enhanced Member Cards Safe to Use in 2026?
Generally Safe
Score 100/100BuddyPress Elevator Pitch – Enhanced Member Cards has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bp-group-members-data" plugin v1.3 exhibits a generally strong security posture regarding its attack surface, with no apparent entry points for direct exploitation like AJAX handlers, REST API routes, or shortcodes. The absence of external HTTP requests and file operations further reduces potential vectors. Furthermore, the presence of nonce checks and the use of prepared statements for all SQL queries are positive security practices. However, a significant concern arises from the complete lack of output escaping. This means that any data rendered by the plugin could be vulnerable to Cross-Site Scripting (XSS) attacks if that data originates from untrusted sources or is manipulated by an attacker. The plugin also has no recorded vulnerability history, which, coupled with the lack of critical code signals and taint flows, suggests a relatively secure codebase to date. Despite the strong foundation, the unescaped output presents a clear and present danger that needs immediate attention to prevent potential XSS vulnerabilities.
Key Concerns
- 0% of outputs properly escaped
BuddyPress Elevator Pitch – Enhanced Member Cards Security Vulnerabilities
BuddyPress Elevator Pitch – Enhanced Member Cards Code Analysis
SQL Query Safety
Output Escaping
BuddyPress Elevator Pitch – Enhanced Member Cards Attack Surface
WordPress Hooks 11
Maintenance & Trust
BuddyPress Elevator Pitch – Enhanced Member Cards Maintenance & Trust
Maintenance Signals
Community Trust
BuddyPress Elevator Pitch – Enhanced Member Cards Alternatives
BuddyKit – Additional features for BuddyPress
buddykit
BuddyKit adds several features like Live Notifications and Media Activities to your BuddyPress powered websites.
What's Hot Activity Tab for BuddyPress
bp-whats-hot
Adds a What's Hot tab to the BuddyPress activity stream.
BuddyPress Edit Activity
buddypress-edit-activity
BuddyPress Edit Activity allows your members to edit their activity posts on the front-end of your BuddyPress-powered site.
Buddypress Sidebar
buddypress-sidebar
This plugin enables you to have multiple sidebars for Buddypress. Create new sidebars that are unique to each page.
Buddypress Friends
buddypress-friends
This plugin adds a widget to Buddypress that displays the friends for the current user that is logged in.
BuddyPress Elevator Pitch – Enhanced Member Cards Developer Profile
3 plugins · 80 total installs
How We Detect BuddyPress Elevator Pitch – Enhanced Member Cards
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bp-group-members-data/admin/js/buddy-profile-admin-scripts.js/wp-content/plugins/bp-group-members-data/admin/css/buddy-profile-admin-styles.css/wp-content/plugins/bp-group-members-data/css/buddy-profile-data.cssadmin/js/buddy-profile-admin-scripts.jsadmin/css/buddy-profile-admin-styles.csscss/buddy-profile-data.cssbp-group-members-data/admin/js/buddy-profile-admin-scripts.js?ver=bp-group-members-data/admin/css/buddy-profile-admin-styles.css?ver=bp-group-members-data/css/buddy-profile-data.css?ver=HTML / DOM Fingerprints
pp-profile-data-pages-listname="card-visibility"id="card-visibility"name="profile-data-pages-form"id="profile-data-pages-form"id="pp-profile-data-pages-list"name="pages[]"+4 more