BuddyPress Messaging Control Security & Risk Analysis

wordpress.org/plugins/bp-messaging-control

This plugin is a Swiss Army Knife for messaging, It allows the site admin to place restrictions on public and private messages including general rules …

80 active installs v1.8.0 PHP + WP + Updated Jul 21, 2024
buddypressmentionsmessagesmessagingprivate-message
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BuddyPress Messaging Control Safe to Use in 2026?

Generally Safe

Score 92/100

BuddyPress Messaging Control has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'bp-messaging-control' v1.8.0 plugin appears to have a strong security posture. The static analysis reveals a remarkably clean codebase with no identified dangerous functions, raw SQL queries, file operations, or external HTTP requests. Furthermore, the plugin demonstrates good security practices with a very high percentage of properly escaped outputs and a robust implementation of nonce and capability checks. The absence of any identified CVEs, past or present, is also a significant positive indicator, suggesting a history of secure development and maintenance.

While the absence of any critical or high-severity findings in the taint analysis is reassuring, the analysis itself covered zero flows. This could indicate a very small attack surface or potentially an incomplete analysis. However, given the other positive metrics, it is more likely that the plugin's design naturally limits complex data flows that would be flagged by taint analysis.

Overall, this plugin exhibits excellent security fundamentals. The minimal attack surface and strong emphasis on input sanitization and authorization checks contribute to a very low-risk profile. The lack of any historical vulnerabilities further reinforces this assessment. The only area for minor consideration is the zero taint flows analyzed, but in the context of all other data, this does not appear to be a significant concern.

Vulnerabilities
None known

BuddyPress Messaging Control Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BuddyPress Messaging Control Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
94 escaped
Nonce Checks
1
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped95 total outputs
Attack Surface

BuddyPress Messaging Control Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 23
actionbp_includebp-messaging-control-loader.php:38
actionwp_enqueue_scriptsbp-messaging-control-loader.php:58
actionwp_print_scriptsbp-messaging-control-loader.php:59
actionwp_enqueue_scriptsbp-messaging-control-loader.php:63
actionbp_initbp-messaging-control-loader.php:68
filterplugin_action_linksbp-messaging-control-loader.php:132
actionbp_before_member_headerbp-messaging-control.php:392
actionbp_nouveau_get_members_buttonsbp-messaging-control.php:395
actionmessages_message_before_savebp-messaging-control.php:563
filterbp_get_message_get_recipient_usernamesbp-messaging-control.php:596
filterbp_get_send_private_message_linkbp-messaging-control.php:618
actionbp_actionsbp-messaging-control.php:628
actionwp_before_admin_bar_renderbp-messaging-control.php:645
filterbp_members_suggestions_get_suggestionsbp-messaging-control.php:647
actionbp_before_messages_compose_contentbp-messaging-control.php:682
filterbp_activity_do_mentionsbp-messaging-control.php:721
filterbp_activity_mentioned_usersbp-messaging-control.php:723
filtermessages_message_content_before_savebp-messaging-control.php:836
filterbp_activity_content_before_savebp-messaging-control.php:851
filterbp_activity_type_before_savebp-messaging-control.php:857
filterbp_email_set_tokensbp-messaging-control.php:907
actionmessages_message_sentbp-messaging-control.php:999
actionbp_core_pre_delete_accountbp-messaging-control.php:1019
Maintenance & Trust

BuddyPress Messaging Control Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedJul 21, 2024
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings2
Active installs80
Developer Profile

BuddyPress Messaging Control Developer Profile

Venutius

20 plugins · 640 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BuddyPress Messaging Control

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bp-messaging-control/css/bp-messaging-control.css/wp-content/plugins/bp-messaging-control/js/bp-messaging-control.js/wp-content/plugins/bp-messaging-control/js/bp-messaging-control-messages.js
Script Paths
/wp-content/plugins/bp-messaging-control/js/bp-messaging-control.js/wp-content/plugins/bp-messaging-control/js/bp-messaging-control-messages.js
Version Parameters
bp-messaging-control/css/bp-messaging-control.css?ver=bp-messaging-control/js/bp-messaging-control.js?ver=bp-messaging-control/js/bp-messaging-control-messages.js?ver=

HTML / DOM Fingerprints

CSS Classes
activity-limitac-form
JS Globals
BPmcMessCntrl
FAQ

Frequently Asked Questions about BuddyPress Messaging Control