BuddyPress Elevator Pitch – Enhanced Member Cards Security & Risk Analysis

wordpress.org/plugins/bp-group-members-data

Choose which fields appear on the "member cards" on member list pages, such as Groups.

20 active installs v1.3 PHP + WP 4.8+ Updated Unknown
bpbuddypresscommunitysocial-networksocial-networking
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BuddyPress Elevator Pitch – Enhanced Member Cards Safe to Use in 2026?

Generally Safe

Score 100/100

BuddyPress Elevator Pitch – Enhanced Member Cards has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "bp-group-members-data" plugin v1.3 exhibits a generally strong security posture regarding its attack surface, with no apparent entry points for direct exploitation like AJAX handlers, REST API routes, or shortcodes. The absence of external HTTP requests and file operations further reduces potential vectors. Furthermore, the presence of nonce checks and the use of prepared statements for all SQL queries are positive security practices. However, a significant concern arises from the complete lack of output escaping. This means that any data rendered by the plugin could be vulnerable to Cross-Site Scripting (XSS) attacks if that data originates from untrusted sources or is manipulated by an attacker. The plugin also has no recorded vulnerability history, which, coupled with the lack of critical code signals and taint flows, suggests a relatively secure codebase to date. Despite the strong foundation, the unescaped output presents a clear and present danger that needs immediate attention to prevent potential XSS vulnerabilities.

Key Concerns

  • 0% of outputs properly escaped
Vulnerabilities
None known

BuddyPress Elevator Pitch – Enhanced Member Cards Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BuddyPress Elevator Pitch – Enhanced Member Cards Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
16
0 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

0% escaped16 total outputs
Attack Surface

BuddyPress Elevator Pitch – Enhanced Member Cards Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_enqueue_scriptsbp-show-profile-data.php:9
actionadmin_enqueue_scriptsbp-show-profile-data.php:10
actionwp_enqueue_scriptsbp-show-profile-data.php:17
actionbp_initbp-show-profile-data.php:20
actionxprofile_field_after_sidebarboxbp-show-profile-data.php:53
actionxprofile_fields_saved_fieldbp-show-profile-data.php:54
actionbp_group_members_list_itembp-show-profile-data.php:371
actionbp_directory_members_itembp-show-profile-data.php:372
actionbp_includeloader.php:18
actionadmin_initloader.php:23
actionadmin_noticesloader.php:27
Maintenance & Trust

BuddyPress Elevator Pitch – Enhanced Member Cards Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedUnknown
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

BuddyPress Elevator Pitch – Enhanced Member Cards Developer Profile

SK

3 plugins · 80 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BuddyPress Elevator Pitch – Enhanced Member Cards

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bp-group-members-data/admin/js/buddy-profile-admin-scripts.js/wp-content/plugins/bp-group-members-data/admin/css/buddy-profile-admin-styles.css/wp-content/plugins/bp-group-members-data/css/buddy-profile-data.css
Script Paths
admin/js/buddy-profile-admin-scripts.jsadmin/css/buddy-profile-admin-styles.csscss/buddy-profile-data.css
Version Parameters
bp-group-members-data/admin/js/buddy-profile-admin-scripts.js?ver=bp-group-members-data/admin/css/buddy-profile-admin-styles.css?ver=bp-group-members-data/css/buddy-profile-data.css?ver=

HTML / DOM Fingerprints

CSS Classes
pp-profile-data-pages-list
Data Attributes
name="card-visibility"id="card-visibility"name="profile-data-pages-form"id="profile-data-pages-form"id="pp-profile-data-pages-list"name="pages[]"+4 more
FAQ

Frequently Asked Questions about BuddyPress Elevator Pitch – Enhanced Member Cards