
Wbcom Designs – BuddyPress Member Reviews Security & Risk Analysis
wordpress.org/plugins/bp-user-profile-reviewsThe BuddyPress Member Reviews plugin enhances the BuddyPress community by empowering registered users to post reviews on other members' profiles.
Is Wbcom Designs – BuddyPress Member Reviews Safe to Use in 2026?
Generally Safe
Score 100/100Wbcom Designs – BuddyPress Member Reviews has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "bp-user-profile-reviews" v3.6.0 plugin exhibits a generally strong security posture based on the provided static analysis. The code demonstrates good practices by utilizing prepared statements for all SQL queries and a high percentage of proper output escaping. Crucially, all identified AJAX handlers and REST API routes appear to have appropriate authentication and permission checks, and no dangerous functions or file operations were detected. The absence of taint analysis findings further suggests a lack of readily apparent code execution vulnerabilities.
However, the plugin's vulnerability history presents a notable concern. A medium severity vulnerability was previously discovered, and although it is currently unpatched, the historical pattern of "Missing Authorization" is a recurring theme. This suggests that while the current version has implemented checks, past issues indicate a potential area for oversight in authorization logic. The presence of 7 AJAX handlers, while all reportedly having checks, still represents a significant attack surface, and any minor oversight in these checks could be exploited.
In conclusion, the "bp-user-profile-reviews" plugin has made significant strides in securing its codebase, particularly in its handling of database queries and output. The absence of critical issues in the current static analysis is encouraging. Nevertheless, the past medium severity vulnerability and the recurring pattern of authorization issues warrant careful consideration and ongoing vigilance to ensure that all entry points remain robustly protected against unauthorized access.
Key Concerns
- Previously unpatched medium severity CVE
- Historical vulnerability: Missing Authorization
- 7 AJAX handlers, potential attack surface
- Minor output escaping deficit (8% not escaped)
Wbcom Designs – BuddyPress Member Reviews Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Wbcom Designs Plugins (Various Versions) - Arbitrary Plugin Installation, Activation and Deactivation
Wbcom Designs – BuddyPress Member Reviews Release Timeline
Wbcom Designs – BuddyPress Member Reviews Code Analysis
SQL Query Safety
Output Escaping
Wbcom Designs – BuddyPress Member Reviews Attack Surface
AJAX Handlers 7
Shortcodes 2
WordPress Hooks 75
Scheduled Events 2
Maintenance & Trust
Wbcom Designs – BuddyPress Member Reviews Maintenance & Trust
Maintenance Signals
Community Trust
Wbcom Designs – BuddyPress Member Reviews Alternatives
BP Profile Search
bp-profile-search
Member search and member directories for BuddyPress and the BuddyBoss Platform.
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress
youzify
The best BuddyPress plugin for building online communities, user profile, social networks, and membership sites on WordPress with tons of features.
BuddyPress Members Only
buddypress-members-only
BuddyPress Members Only restricts Your Buddypress and Wordpress to logged in/registered members.
RumbleTalk Live Group Chat – HTML5
rumbletalk-chat-a-chat-with-themes
Live group chat plugin for WordPress. Integrate it into your website in minutes. Create one or multiple rooms effortlessly.
Wbcom Designs – Shortcodes & Elementor Widgets For BuddyPress
shortcodes-for-buddypress
This plugin generates shortcodes for Listing Activity Streams, Members, and Groups on any website post or page.
Wbcom Designs – BuddyPress Member Reviews Developer Profile
19 plugins · 10K total installs
How We Detect Wbcom Designs – BuddyPress Member Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bp-user-profile-reviews/admin/css/bp-member-review-admin.css/wp-content/plugins/bp-user-profile-reviews/admin/js/bp-member-review-admin.js/wp-content/plugins/bp-user-profile-reviews/css/bp-user-profile-reviews.css/wp-content/plugins/bp-user-profile-reviews/js/bp-user-profile-reviews.js/wp-content/plugins/bp-user-profile-reviews/admin/js/bp-member-review-admin.js/wp-content/plugins/bp-user-profile-reviews/js/bp-user-profile-reviews.jsbp-user-profile-reviews/admin/css/bp-member-review-admin.css?ver=bp-user-profile-reviews/admin/js/bp-member-review-admin.js?ver=bp-user-profile-reviews/css/bp-user-profile-reviews.css?ver=bp-user-profile-reviews/js/bp-user-profile-reviews.js?ver=HTML / DOM Fingerprints
bp-member-reviews-wrapperbp-member-reviews-single-reviewbp-member-reviews-rating-formbp-member-reviews-review-listbupr-admin-settingsdata-bp-member-review-iddata-bp-member-review-noncebp_member_reviews_ajax_object[bp_member_reviews][bp_member_rating_form]