BP Search Block Security & Risk Analysis

wordpress.org/plugins/bp-search-block

The BP Search Block is a BuddyPress Block to search for the content shared into your community site!

600 active installs v1.1.0 PHP 5.6+ WP 5.8+ Updated Aug 11, 2024
blockbuddypresscommunitysearch
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BP Search Block Safe to Use in 2026?

Generally Safe

Score 92/100

BP Search Block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "bp-search-block" plugin version 1.1.0 exhibits a strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals no dangerous functions, no direct SQL queries (all use prepared statements), and all identified outputs are properly escaped. Furthermore, there are no file operations, external HTTP requests, or indications of insecure handling of user input through taint analysis.

Critically, the plugin has no known vulnerabilities (CVEs) and a complete absence of previously recorded security incidents suggests a history of responsible development and maintenance. The attack surface is also minimal, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed directly by the plugin.

While the lack of explicit capability checks or nonce checks on the identified zero entry points is technically a concern, it's mitigated by the fact that there are no entry points to begin with. Overall, this plugin appears to be very secure, with no immediate threats identified from the provided data. Its strengths lie in its clean code, absence of vulnerabilities, and minimal attack surface.

Vulnerabilities
None known

BP Search Block Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

BP Search Block Release Timeline

v1.1.0Current
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

BP Search Block Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

BP Search Block Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionbp_core_blocks_initbp-search-block.php:59
Maintenance & Trust

BP Search Block Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedAug 11, 2024
PHP min version5.6
Downloads14K

Community Trust

Rating80/100
Number of ratings1
Active installs600
Developer Profile

BP Search Block Developer Profile

Mathieu Viet

7 plugins · 2K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BP Search Block

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bp-search-block/assets/search.svg
Script Paths
bp-search-form-editor-scriptbp-search-form-style

HTML / DOM Fingerprints

CSS Classes
bp-search-block-icon
JS Globals
window.bpSearchFormAction
FAQ

Frequently Asked Questions about BP Search Block