
Profile Field Duplicator for BuddyPress Security & Risk Analysis
wordpress.org/plugins/bp-profile-field-duplicatorMake a duplicate of BuddyPress profile fields in one click.
Is Profile Field Duplicator for BuddyPress Safe to Use in 2026?
Generally Safe
Score 100/100Profile Field Duplicator for BuddyPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bp-profile-field-duplicator" v1.2.0 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The code adheres to several WordPress security best practices, including the exclusive use of prepared statements for SQL queries, proper output escaping for all identified outputs, and the inclusion of a nonce check. Furthermore, the absence of any known CVEs and the lack of any identified taint flows or dangerous functions suggest a generally secure development approach. The plugin's attack surface is minimal and all identified entry points are protected. However, a minor area for improvement lies in the lack of capability checks on the single AJAX handler. While this handler is currently the only entry point and is otherwise protected, relying solely on nonces without explicit capability checks could, in theory, be a less robust defense against certain sophisticated attacks if other protections were to fail. Despite this, the overall picture is positive, indicating a well-maintained and secure plugin.
Key Concerns
- AJAX handler without capability check
Profile Field Duplicator for BuddyPress Security Vulnerabilities
Profile Field Duplicator for BuddyPress Code Analysis
Output Escaping
Profile Field Duplicator for BuddyPress Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
Profile Field Duplicator for BuddyPress Maintenance & Trust
Maintenance Signals
Community Trust
Profile Field Duplicator for BuddyPress Alternatives
BuddyPress Xprofile Custom Field Types
bp-xprofile-custom-field-types
Buddypress Xprofile Custom Field Types adds extra custom profile fields to BuddyPress. Field types are: Birthdate, Email, Url etc.
Advanced XProfile Fields for BuddyPress
advanced-xprofile-fields-for-buddypress
Enhance your BuddyPress profile fields with Advanced XProfile Fields for BuddyPress. Manage fields labels, validation and show fields in admin.
BuddyPress Conditional Field Groups
buddypress-conditional-field-groups
Conditionally hide BuddyPress XProfile Field Groups based on user role.
Buddypress XProfile Custom Field Types Reloaded
bp-xprofile-custom-fields
Extends the default Buddypress XProfile field types you can set for profile. Some XProfile Field types are: Birthdate, Email, Url, Datepicker, Checkbo …
Profile Field Repeater
bp-profile-field-repeater
Make TEXT BOX or NUMBER type BuddyPress profile field as a repeater.
Profile Field Duplicator for BuddyPress Developer Profile
12 plugins · 250 total installs
How We Detect Profile Field Duplicator for BuddyPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bp-profile-field-duplicator/assets/js/plugin.min.js/wp-content/plugins/bp-profile-field-duplicator/assets/js/plugin.min.jsbp-profile-field-duplicator/assets/js/plugin.min.js?ver=HTML / DOM Fingerprints
bppfc_duplicatordata-idbppfc_obj