
BP Group Reviews Security & Risk Analysis
wordpress.org/plugins/bp-group-reviewsAdds a reviews/rating section to BuddyPress groups. As seen on the buddypress.org/extend/plugins
Is BP Group Reviews Safe to Use in 2026?
Generally Safe
Score 85/100BP Group Reviews has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bp-group-reviews" plugin v1.3.2 exhibits a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities (CVEs), no external HTTP requests, no file operations, and all SQL queries are properly prepared. The static analysis also shows a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed. Taint analysis found no critical or high severity issues, indicating no immediately obvious pathways for data injection or compromise based on that analysis. This suggests a generally cautious approach to some core security areas.
However, several concerns are present. The use of the `create_function` PHP function is a significant red flag. While its direct impact isn't quantifiable without specific taint flow analysis, `create_function` is considered a deprecated and dangerous function due to its ability to execute arbitrary code and its inherent security risks, often leading to vulnerabilities if not handled with extreme care. Furthermore, only 15% of output is properly escaped. This indicates a high potential for Cross-Site Scripting (XSS) vulnerabilities across the plugin's output, which could be exploited to inject malicious scripts into users' browsers.
The lack of recorded vulnerabilities in its history is a positive indicator, suggesting the developers have either been diligent or the plugin hasn't been a target. However, this can also be a reflection of limited testing or auditing. The combination of a dangerous function and widespread unescaped output presents a substantial risk despite the absence of publicly known CVEs. The plugin has strengths in its limited attack surface and secure SQL practices, but the identified code quality issues present tangible risks.
Key Concerns
- Use of dangerous function create_function
- Low percentage of properly escaped output
BP Group Reviews Security Vulnerabilities
BP Group Reviews Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
BP Group Reviews Attack Surface
WordPress Hooks 24
Maintenance & Trust
BP Group Reviews Maintenance & Trust
Maintenance Signals
Community Trust
BP Group Reviews Alternatives
Registration Options for BuddyPress
bp-registration-options
Moderate new BuddyPress members and fight BuddyPress spam.
BuddyPress Group Email Subscription
buddypress-group-email-subscription
This powerful plugin allows users to receive email notifications of group activity. Weekly or daily digests are available.
Wbcom Designs – Shortcodes & Elementor Widgets For BuddyPress
shortcodes-for-buddypress
This plugin generates shortcodes for Listing Activity Streams, Members, and Groups on any website post or page.
BuddyPress Default Data
bp-default-data
Plugin will create lots of users, messages, friends connections, groups, topics, activity items, profile data - useful for testing purpose.
BuddyPress Groups Extras
buddypress-groups-extras
Introduce custom fields and custom pages to your BuddyPress-powered groups.
BP Group Reviews Developer Profile
27 plugins · 12K total installs
How We Detect BP Group Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bp-group-reviews/css/group-reviews.css/wp-content/plugins/bp-group-reviews/js/group-reviews.js/wp-content/plugins/bp-group-reviews/js/group-reviews.jsHTML / DOM Fingerprints
bpgr-ratingbpgr