
BP Profile Status Security & Risk Analysis
wordpress.org/plugins/bp-profile-statusUsing BP Profile Status plugin you can set status in your BuddyPress Profile.
Is BP Profile Status Safe to Use in 2026?
Generally Safe
Score 100/100BP Profile Status has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'bp-profile-status' plugin v1.5.1 exhibits a mixed security posture. On the positive side, the code demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and all identified output points are properly escaped. Furthermore, there is a complete absence of known vulnerabilities (CVEs) and no concerning taint analysis results were reported, indicating a clean history and a lack of exploitable data flow issues.
However, a significant concern arises from the plugin's attack surface. All three identified AJAX handlers lack authentication checks. This creates a substantial risk, as unauthenticated users could potentially interact with these endpoints, leading to unintended actions or information disclosure. While the absence of direct SQL injection or cross-site scripting vulnerabilities is commendable, the lack of proper authorization on these entry points is a critical oversight that needs immediate attention.
In conclusion, while the plugin benefits from a clean vulnerability history and secure handling of database queries and output, the presence of unprotected AJAX endpoints presents a serious security weakness. This aspect overshadows the otherwise positive coding practices and requires remediation to ensure the plugin's overall security.
Key Concerns
- AJAX handlers without auth checks
- Large attack surface without auth
BP Profile Status Security Vulnerabilities
BP Profile Status Release Timeline
BP Profile Status Code Analysis
Output Escaping
BP Profile Status Attack Surface
AJAX Handlers 3
WordPress Hooks 8
Maintenance & Trust
BP Profile Status Maintenance & Trust
Maintenance Signals
Community Trust
BP Profile Status Alternatives
BuddyPress Xprofile Custom Field Types
bp-xprofile-custom-field-types
Buddypress Xprofile Custom Field Types adds extra custom profile fields to BuddyPress. Field types are: Birthdate, Email, Url etc.
NodeInfo(2)
nodeinfo
NodeInfo and NodeInfo2 for WordPress!
WebFinger
webfinger
WebFinger for WordPress
BuddyPress Edit Activity
buddypress-edit-activity
BuddyPress Edit Activity allows your members to edit their activity posts on the front-end of your BuddyPress-powered site.
BuddyPress & BuddyBoss Member Profile Forms
buddyforms-members
Create custom Member Profile Tabs and Registration Forms in BuddyPress and BuddyBoss. Allow your Members to create, edit, and delete any kind of data …
BP Profile Status Developer Profile
4 plugins · 160 total installs
How We Detect BP Profile Status
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bp-profile-status/public/css/bp-profile-status-public.css/wp-content/plugins/bp-profile-status/public/js/bp-profile-status-public.js/wp-content/plugins/bp-profile-status/public/js/bp-profile-status-public.js/wp-content/plugins/bp-profile-status/public/css/bp-profile-status-public.css?ver=/wp-content/plugins/bp-profile-status/public/js/bp-profile-status-public.js?ver=HTML / DOM Fingerprints
bp-profile-status-user-statusbpps_ajax_object