
Pinned Feed Notices for BuddyPress Security & Risk Analysis
wordpress.org/plugins/bp-pinned-feed-noticesAdd custom notices to the top of the main activity feed.
Is Pinned Feed Notices for BuddyPress Safe to Use in 2026?
Generally Safe
Score 100/100Pinned Feed Notices for BuddyPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bp-pinned-feed-notices" plugin v1.0.3 exhibits a generally good security posture based on the provided static analysis. There are no identified critical or high severity vulnerabilities in the code, no known CVEs, and the plugin utilizes prepared statements for SQL queries, which is a strong security practice. The presence of a nonce check on its single AJAX handler is also commendable. However, a notable concern is the absence of capability checks on the AJAX handler. While a nonce check prevents basic CSRF attacks, it doesn't verify if the logged-in user has the necessary permissions to perform the action, potentially leading to privilege escalation if the action is sensitive. The code analysis also indicates that 29% of output is not properly escaped, which, while not rated as critical in this analysis, can open the door to cross-site scripting (XSS) vulnerabilities if the unescaped data is user-controlled.
Key Concerns
- Missing capability checks on AJAX handler
- Significant portion of output not properly escaped
Pinned Feed Notices for BuddyPress Security Vulnerabilities
Pinned Feed Notices for BuddyPress Release Timeline
Pinned Feed Notices for BuddyPress Code Analysis
Output Escaping
Pinned Feed Notices for BuddyPress Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
Pinned Feed Notices for BuddyPress Maintenance & Trust
Maintenance Signals
Community Trust
Pinned Feed Notices for BuddyPress Alternatives
Activity Feed Anywhere For BuddyBoss
activity-feed-anywhere-for-buddyboss
Activity Feed Anywhere For BuddyBoss adds a native BuddyBoss activity post box and/or feed on any page.
BP Lotsa Feeds
bp-lotsa-feeds
Gives your BuddyPress installation lotsa feeds.
BuddyPress Group Twitter
buddypress-group-twitter
Attach Twitter accounts to a BuddyPress group then aggregate and track tweets within that group.
BP External Group Blogs
external-group-blogs
Give group creators and administrators on your BuddyPress install the ability to attach
YD BuddyPress Feed Syndication
yd-buddypress-feed-syndication
Syndicate RSS feeds into your user or group Activity stream
Pinned Feed Notices for BuddyPress Developer Profile
5 plugins · 880 total installs
How We Detect Pinned Feed Notices for BuddyPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bp-pinned-feed-notices/assets/css/bp-pinned-feed-notices.css/wp-content/plugins/bp-pinned-feed-notices/assets/js/bp-pinned-feed-notices.js/wp-content/plugins/bp-pinned-feed-notices/assets/js/bp-pinned-feed-notices.jsbp-pinned-feed-notices/assets/css/bp-pinned-feed-notices.css?ver=bp-pinned-feed-notices/assets/js/bp-pinned-feed-notices.js?ver=HTML / DOM Fingerprints
BPPfnAjaxObject