
BuddyPress Poke Security & Risk Analysis
wordpress.org/plugins/bp-pokeBuddyPress Poke Plugin allow members to poke users just like facebook.
Is BuddyPress Poke Safe to Use in 2026?
Generally Safe
Score 85/100BuddyPress Poke has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The bp-poke plugin version 1.1.2 presents a mixed security posture. On the positive side, it shows a strong adherence to secure database practices with all SQL queries utilizing prepared statements and no known past vulnerabilities, indicating a potentially stable development history. It also avoids dangerous functions, file operations, and external HTTP requests, which are common attack vectors.
However, significant concerns arise from the static analysis. The plugin has a single unprotected AJAX handler, representing a direct entry point for attackers without any authentication or authorization checks. Furthermore, all output in the plugin is unescaped, making it highly susceptible to Cross-Site Scripting (XSS) vulnerabilities where malicious code could be injected and executed in a user's browser.
While the lack of past CVEs and taint analysis findings is encouraging, it doesn't negate the immediate risks identified in the code. The unprotected AJAX handler and unescaped output are critical weaknesses that could be exploited to compromise user data or the integrity of the WordPress site. The plugin's strengths in secure database practices are overshadowed by these critical vulnerabilities.
Key Concerns
- AJAX handler without authentication checks
- No output escaping on any outputs
BuddyPress Poke Security Vulnerabilities
BuddyPress Poke Release Timeline
BuddyPress Poke Code Analysis
Output Escaping
BuddyPress Poke Attack Surface
AJAX Handlers 1
WordPress Hooks 12
Maintenance & Trust
BuddyPress Poke Maintenance & Trust
Maintenance Signals
Community Trust
BuddyPress Poke Alternatives
BP Profile Search
bp-profile-search
Member search and member directories for BuddyPress and the BuddyBoss Platform.
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress
youzify
The best BuddyPress plugin for building online communities, user profile, social networks, and membership sites on WordPress with tons of features.
Bulk Edit and Create User Profiles – WP Sheet Editor
bulk-edit-user-profiles-in-spreadsheet
Modern Bulk Editor for Users and Profiles, create and edit hundreds of users in a spreadsheet inside wp-admin. Quick edits.
Dynamic User Directory
dynamic-user-directory
Powerful and feature-rich user directory based on user profile meta fields.
JSON API User
json-api-user
Extends the JSON API Plugin to allow RESTful user registration, authentication & many other User Meta, BP functions. A Pro version is also available.
BuddyPress Poke Developer Profile
15 plugins · 15K total installs
How We Detect BuddyPress Poke
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bp-poke/css/style.css/wp-content/plugins/bp-poke/js/poke.js/wp-content/plugins/bp-poke/js/poke.jsbp-poke/css/style.css?ver=bp-poke/js/poke.js?ver=HTML / DOM Fingerprints
bp-poke-user-listbp-poke-user-list-itemdata-poke-user-idbp_poke