BP Memories Security & Risk Analysis

wordpress.org/plugins/bp-memories

Using BP Memories you can see your memory regarding BuddyPress such as activity.

10 active installs v1.1.0 PHP + WP 4.0+ Updated Jul 10, 2017
bp-memoriesbuddypressmemoriesmemory
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BP Memories Safe to Use in 2026?

Generally Safe

Score 85/100

BP Memories has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'bp-memories' plugin version 1.1.0 demonstrates a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with insufficient authentication or permission checks significantly limits the plugin's attack surface. Furthermore, the code signals indicate good development practices, with no dangerous functions, all SQL queries using prepared statements, and a high percentage of output being properly escaped. The lack of file operations and external HTTP requests further reduces potential vulnerabilities. The plugin also shows no history of known CVEs, suggesting a consistent focus on security by its developers.

While the static analysis reveals a clean codebase with no critical or high-severity taint flows, and the vulnerability history is empty, there are minor areas for potential improvement. The absence of nonce checks and capability checks, while not directly exploitable due to the limited attack surface, represents a missed opportunity to further harden the plugin. However, given the current lack of entry points that would require these checks and the absence of any past vulnerabilities, the overall risk is currently very low. The plugin is well-developed from a security perspective, with strengths in its limited attack surface and secure coding practices.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
  • Minor output escaping concern (4% unescaped)
Vulnerabilities
None known

BP Memories Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

BP Memories Release Timeline

v1.1.0Current
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

BP Memories Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
1
24 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

96% escaped25 total outputs
Attack Surface

BP Memories Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionplugins_loadedincludes\class-bp-memories.php:152
actioninitincludes\class-bp-memories.php:168
filterbp_directory_pagesincludes\class-bp-memories.php:170
filterbp_core_get_directory_page_idsincludes\class-bp-memories.php:171
filterplugin_action_linksincludes\class-bp-memories.php:174
filternetwork_admin_plugin_action_linksincludes\class-bp-memories.php:175
actionwp_enqueue_scriptsincludes\class-bp-memories.php:191
actionbp_before_activity_loopincludes\class-bp-memories.php:196
filterthe_contentincludes\class-bp-memories.php:199
Maintenance & Trust

BP Memories Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedJul 10, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

BP Memories Developer Profile

Sanket Parmar

4 plugins · 160 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BP Memories

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bp-memories/public/css/bp-memories-public.css/wp-content/plugins/bp-memories/public/js/bp-memories-public.js
Script Paths
/wp-content/plugins/bp-memories/public/js/bp-memories-public.js
Version Parameters
/wp-content/plugins/bp-memories/public/css/bp-memories-public.css?ver=/wp-content/plugins/bp-memories/public/js/bp-memories-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
bp-memories-wrap
JS Globals
bp_memories_params
Shortcode Output
[bp_memories]
FAQ

Frequently Asked Questions about BP Memories