
BP Mutual Friends Security & Risk Analysis
wordpress.org/plugins/bp-mutual-friendsList users' mutual friends in BuddyPress easily. One click install and setup.
Is BP Mutual Friends Safe to Use in 2026?
Generally Safe
Score 85/100BP Mutual Friends has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The bp-mutual-friends v1.0.0 plugin exhibits a seemingly strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries are all prepared, and there are no file operations or external HTTP requests. The absence of known vulnerabilities in its history further suggests a well-maintained and secure plugin. However, a critical concern emerges from the code analysis: 100% of identified outputs are not properly escaped. This oversight creates a significant risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into pages rendered by the plugin. Additionally, the complete absence of nonce checks and capability checks on any entry points, while the attack surface is reported as zero, raises questions. If any entry points were to be discovered or introduced in future versions without proper checks, this lack of foundational security measures would be a major liability. The vulnerability history is clean, which is positive, but it does not negate the immediate risks identified in the code analysis.
Key Concerns
- Output not properly escaped
- No nonce checks
- No capability checks
BP Mutual Friends Security Vulnerabilities
BP Mutual Friends Code Analysis
SQL Query Safety
Output Escaping
BP Mutual Friends Attack Surface
WordPress Hooks 7
Maintenance & Trust
BP Mutual Friends Maintenance & Trust
Maintenance Signals
Community Trust
BP Mutual Friends Alternatives
Mutual Buddies
mutual-buddies
Mutual buddies displays BuddyPress mutual friends of the logged in user & the user whose profile the user is looking at on the Profile page.
Buddypress Friends
buddypress-friends
This plugin adds a widget to Buddypress that displays the friends for the current user that is logged in.
Invite Anyone
invite-anyone
Makes BuddyPress's invitation features more powerful.
BuddyPress Extended Friendship Request
buddypress-extended-friendship-request
BuddyPress Extended Friendship Request plugin allows users to send a personalized message with the friendship requests.
BuddyPress Automatic Friends
bp-automatic-friends
Automatically create and accept friendships for specified users upon new user registration. * Requires BuddyPress
BP Mutual Friends Developer Profile
17 plugins · 2K total installs
How We Detect BP Mutual Friends
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bp-mutual-friends/css/mutual-friends.cssbp-mutual-friends/css/mutual-friends.css?ver=HTML / DOM Fingerprints
mutual-friends<!-- .item-list-tabs --><!-- Mutual Friends -->