BuddyPress Ninja Security & Risk Analysis

wordpress.org/plugins/bp-ninja

Site admins can use stealth mode to hide their last activity.

10 active installs v0.2 PHP + WP + Updated Sep 19, 2011
buddypressstealth
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BuddyPress Ninja Safe to Use in 2026?

Generally Safe

Score 85/100

BuddyPress Ninja has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "bp-ninja" v0.2 plugin exhibits an exceptionally strong security posture. The static analysis reveals a complete absence of exposed attack surface, including AJAX handlers, REST API routes, shortcodes, and cron events. Furthermore, the code adheres to best practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and properly escaping all outputs. The plugin also avoids file operations, external HTTP requests, and importantly, has zero nonces or capability checks, which in this context, likely indicates a design that doesn't require them due to the lack of entry points, rather than a security oversight. The taint analysis shows no detected unsanitized flows, reinforcing the impression of secure coding. The vulnerability history is equally reassuring, with no known CVEs, both historical and current. This data suggests a highly secure plugin, with a proactive approach to security development, or perhaps a very narrowly focused functionality with no exploitable entry points in this version.

Vulnerabilities
None known

BuddyPress Ninja Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

BuddyPress Ninja Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

BuddyPress Ninja Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

BuddyPress Ninja Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionbp_initbp-ninja.php:30
actionbp_adminbar_menusbp-ninja.php:60
actionwpmu_delete_userbp-ninja.php:91
actiondelete_userbp-ninja.php:92
actionbp_make_spam_userbp-ninja.php:93
Maintenance & Trust

BuddyPress Ninja Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedSep 19, 2011
PHP min version
Downloads5K

Community Trust

Rating60/100
Number of ratings2
Active installs10
Developer Profile

BuddyPress Ninja Developer Profile

francescolaffi

3 plugins · 90 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BuddyPress Ninja

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
bp-adminbar-ninja-menu
FAQ

Frequently Asked Questions about BuddyPress Ninja