Profile Field Duplicator for BuddyPress Security & Risk Analysis

wordpress.org/plugins/bp-profile-field-duplicator

Make a duplicate of BuddyPress profile fields in one click.

10 active installs v1.2.0 PHP 5.6+ WP 4.0+ Updated Unknown
buddypressduplicateprofile-field
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Profile Field Duplicator for BuddyPress Safe to Use in 2026?

Generally Safe

Score 100/100

Profile Field Duplicator for BuddyPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "bp-profile-field-duplicator" v1.2.0 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The code adheres to several WordPress security best practices, including the exclusive use of prepared statements for SQL queries, proper output escaping for all identified outputs, and the inclusion of a nonce check. Furthermore, the absence of any known CVEs and the lack of any identified taint flows or dangerous functions suggest a generally secure development approach. The plugin's attack surface is minimal and all identified entry points are protected. However, a minor area for improvement lies in the lack of capability checks on the single AJAX handler. While this handler is currently the only entry point and is otherwise protected, relying solely on nonces without explicit capability checks could, in theory, be a less robust defense against certain sophisticated attacks if other protections were to fail. Despite this, the overall picture is positive, indicating a well-maintained and secure plugin.

Key Concerns

  • AJAX handler without capability check
Vulnerabilities
None known

Profile Field Duplicator for BuddyPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Profile Field Duplicator for BuddyPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
7 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped7 total outputs
Attack Surface

Profile Field Duplicator for BuddyPress Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_bppfc_duplicate_fieldapp\admin\class-bp-profile-field-duplicator-admin.php:37
WordPress Hooks 4
actionxprofile_admin_field_actionapp\admin\class-bp-profile-field-duplicator-admin.php:31
actionadmin_enqueue_scriptsapp\admin\class-bp-profile-field-duplicator-admin.php:34
actionplugins_loadedbp-profile-field-duplicator.php:61
actionadmin_noticesbp-profile-field-duplicator.php:94
Maintenance & Trust

Profile Field Duplicator for BuddyPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Profile Field Duplicator for BuddyPress Developer Profile

Bunty

12 plugins · 250 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Profile Field Duplicator for BuddyPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bp-profile-field-duplicator/assets/js/plugin.min.js
Script Paths
/wp-content/plugins/bp-profile-field-duplicator/assets/js/plugin.min.js
Version Parameters
bp-profile-field-duplicator/assets/js/plugin.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
bppfc_duplicator
Data Attributes
data-id
JS Globals
bppfc_obj
FAQ

Frequently Asked Questions about Profile Field Duplicator for BuddyPress