Wbcom Designs – BuddyPress Post from Anywhere Security & Risk Analysis

wordpress.org/plugins/bp-post-from-anywhere

Transform any page into a community engagement hub! Let your members share updates, connect, and interact from anywhere on your website with just one …

100 active installs v1.5.7 PHP 7.4+ WP 5.0+ Updated Jan 29, 2026
activity-postspost-form
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wbcom Designs – BuddyPress Post from Anywhere Safe to Use in 2026?

Generally Safe

Score 100/100

Wbcom Designs – BuddyPress Post from Anywhere has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "bp-post-from-anywhere" v1.5.7 plugin exhibits a generally good security posture based on the provided static analysis. The absence of vulnerable AJAX handlers, REST API routes, cron events, and file operations significantly limits the plugin's attack surface. Furthermore, the exclusive use of prepared statements for SQL queries and the presence of nonce and capability checks indicate adherence to common WordPress security best practices. Taint analysis revealed no unsanitized paths or critical/high severity flows, which is a very positive sign. The lack of any recorded vulnerabilities, past or present, further reinforces the impression of a well-maintained and secure plugin.

However, the plugin does have one shortcode, which is its sole entry point identified. While this shortcode is not directly flagged as unprotected, any functionality exposed through shortcodes always warrants careful review, as their context of execution can sometimes lead to unexpected vulnerabilities if not handled with utmost care. The static analysis also indicates that 39% of output is not properly escaped. This is a notable concern, as unescaped output can lead to Cross-Site Scripting (XSS) vulnerabilities, especially if dynamic data is included in these outputs. Despite the generally positive indicators, this significant percentage of unescaped output presents a potential risk that should be addressed.

In conclusion, "bp-post-from-anywhere" v1.5.7 appears to be a secure plugin with a strong foundation, evidenced by its minimal attack surface and lack of historical vulnerabilities. The use of prepared statements and the inclusion of security checks are commendable. The primary area for improvement lies in addressing the substantial amount of unescaped output, which could expose users to XSS attacks. The presence of a single shortcode as the entry point is not inherently a risk, but it remains a potential area for future scrutiny.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Wbcom Designs – BuddyPress Post from Anywhere Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Wbcom Designs – BuddyPress Post from Anywhere Release Timeline

v1.5.7Current
v1.5.6
v1.5.2
v1.5.1
v1.5.0
v1.4.0
v1.3.0
v1.2.0
v1.1.0
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Wbcom Designs – BuddyPress Post from Anywhere Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
19 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

61% escaped31 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<bp-post-from-activity> (includes\templates\bp-post-from-activity.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Wbcom Designs – BuddyPress Post from Anywhere Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[bppfa_postform] includes\class-bp-post-from-anywhere.php:173
WordPress Hooks 11
actionadmin_initadmin\class-bp-anywhere-feedback.php:77
actionadmin_noticesadmin\class-bp-anywhere-feedback.php:112
actioninitadmin\class-bp-anywhere-feedback.php:267
actionadmin_initbp-post-from-anywhere.php:53
actionadmin_noticesbp-post-from-anywhere.php:54
actionplugins_loadedbp-post-from-anywhere.php:103
actionplugins_loadedincludes\class-bp-post-from-anywhere.php:158
actionadmin_enqueue_scriptsincludes\class-bp-post-from-anywhere.php:171
actionadmin_enqueue_scriptsincludes\class-bp-post-from-anywhere.php:172
actionwp_enqueue_scriptsincludes\class-bp-post-from-anywhere.php:187
actionwp_enqueue_scriptsincludes\class-bp-post-from-anywhere.php:188
Maintenance & Trust

Wbcom Designs – BuddyPress Post from Anywhere Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 29, 2026
PHP min version7.4
Downloads8K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Wbcom Designs – BuddyPress Post from Anywhere Developer Profile

wbcomdesigns

19 plugins · 10K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
807 days
View full developer profile
Detection Fingerprints

How We Detect Wbcom Designs – BuddyPress Post from Anywhere

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bp-post-from-anywhere/assets/css/bp-post-from-anywhere-admin.css/wp-content/plugins/bp-post-from-anywhere/assets/js/bp-post-from-anywhere-admin.js/wp-content/plugins/bp-post-from-anywhere/assets/js/bp-post-from-anywhere-public.js
Script Paths
/wp-content/plugins/bp-post-from-anywhere/assets/js/bp-post-from-anywhere-admin.js/wp-content/plugins/bp-post-from-anywhere/assets/js/bp-post-from-anywhere-public.js
Version Parameters
bp-post-from-anywhere/assets/css/bp-post-from-anywhere-admin.css?ver=bp-post-from-anywhere/assets/js/bp-post-from-anywhere-admin.js?ver=bp-post-from-anywhere/assets/js/bp-post-from-anywhere-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
bppfa-buddypressbppfa-post-form-wrap
Data Attributes
data-noncedata-ajaxurldata-pluginurl
JS Globals
bppfa_admin_objbppfa_public_obj
Shortcode Output
<div id="bppfa-buddypress"><div id="bppfa-post-form-wrap">
FAQ

Frequently Asked Questions about Wbcom Designs – BuddyPress Post from Anywhere