BP Resume Page Security & Risk Analysis

wordpress.org/plugins/bp-resume-page

Adds a resume page to BuddyPress profile. Also adds nav menu item under Avatar and in admin bar.

10 active installs v1.0 PHP + WP 3.0+ Updated Jun 4, 2012
buddybuddypresseducationprofessionresume
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BP Resume Page Safe to Use in 2026?

Generally Safe

Score 85/100

BP Resume Page has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The 'bp-resume-page' v1.0 plugin exhibits a generally positive security posture with no recorded vulnerabilities and a lack of known dangerous functions or external HTTP requests. The code analysis indicates a commendable use of prepared statements for SQL queries. However, a significant concern arises from the complete absence of output escaping for all 17 identified output points. This means that any user-supplied data displayed on the frontend is potentially vulnerable to cross-site scripting (XSS) attacks, as it is not being properly neutralized before rendering.

While the plugin has no recorded vulnerability history, its current static analysis results highlight a critical oversight in output sanitization. The lack of taint analysis flows is likely due to the limited attack surface and absence of direct user input handling in the analyzed entry points. Nevertheless, the unescaped output presents a clear and present risk that needs immediate attention. The plugin's strengths lie in its minimal attack surface and secure SQL practices, but the failure to escape output is a serious weakness that significantly elevates its risk profile.

Key Concerns

  • All outputs are unescaped
Vulnerabilities
None known

BP Resume Page Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

BP Resume Page Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
0 escaped
Nonce Checks
0
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped17 total outputs
Attack Surface

BP Resume Page Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionbp_initbp-resume-page.php:21
actionbp_template_contentbp-resume-page.php:68
Maintenance & Trust

BP Resume Page Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedJun 4, 2012
PHP min version
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

BP Resume Page Developer Profile

fmeroney

2 plugins · 30 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BP Resume Page

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bp-resume-page/pages/style.php/wp-content/plugins/bp-resume-page/pages/view.php/wp-content/plugins/bp-resume-page/pages/edit.php/wp-content/plugins/bp-resume-page/pages/countries.php

HTML / DOM Fingerprints

CSS Classes
bprp-updatedbprp-viewbprp-sectiondetails-itemdel-buttonbprp-buttontop-containerbprp-form+7 more
Data Attributes
data-id
FAQ

Frequently Asked Questions about BP Resume Page