
BP Member Reviews Security & Risk Analysis
wordpress.org/plugins/bp-user-reviewsAdd to your BuddyPress community the ability to provide reviews and star ratings for the members.
Is BP Member Reviews Safe to Use in 2026?
Generally Safe
Score 85/100BP Member Reviews has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bp-user-reviews" plugin v1.2.6 exhibits a generally strong security posture based on the provided static analysis. The absence of critical taint flows, raw SQL queries, and a significant number of properly escaped outputs are positive indicators. Furthermore, the plugin demonstrates good practice by implementing nonce checks and capability checks on its AJAX handlers, which represent its entire identified attack surface. The lack of any recorded vulnerabilities or CVEs further bolsters this positive assessment, suggesting a well-maintained and secure codebase. However, the relatively low percentage of properly escaped outputs (46%) does present a potential area of concern. While no specific vulnerabilities are directly indicated by this, it suggests that cross-site scripting (XSS) could be a theoretical risk if sensitive data is handled within the unescaped outputs. Therefore, while the plugin appears secure in its current state, ongoing vigilance regarding output escaping is recommended.
Key Concerns
- Low percentage of properly escaped outputs
BP Member Reviews Security Vulnerabilities
BP Member Reviews Code Analysis
Output Escaping
BP Member Reviews Attack Surface
AJAX Handlers 2
WordPress Hooks 29
Maintenance & Trust
BP Member Reviews Maintenance & Trust
Maintenance Signals
Community Trust
BP Member Reviews Alternatives
CBX User Online & Last Login
cbxuseronline
Shows online users based on cookie for guest and session for registered user. It also records the last login of user.
WP Notification Bell
wp-notification-bell
On-site bell notifications. Display notifications custom or triggered (new posts/cpts, WooCommerce order updates, new comment replies, bbPress...)
bbPress Login Register Links On Forum Topic Pages
bbpress-login-register-links-on-forum-topic-pages
Add bbPress only sidebar, Add bbpress login link, bbpress register link, forget password link, log out link in bbpress forum index pages or bbpress si …
bbPress Voting
bbp-voting
Let visitors vote up and down on bbPress topics and replies just like Reddit or Stack Overflow!
bbPress Messages
bbp-messages
bbPress Messages - Simple yet powerful private messaging system tailored for bbPress.
BP Member Reviews Developer Profile
2 plugins · 10K total installs
How We Detect BP Member Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bp-user-reviews/css/bp-user-reviews.css/wp-content/plugins/bp-user-reviews/css/bp-user-reviews-admin.css/wp-content/plugins/bp-user-reviews/js/bp-user-reviews.js/wp-content/plugins/bp-user-reviews/js/bp-user-reviews-admin.js/wp-content/plugins/bp-user-reviews/js/bp-user-reviews.js/wp-content/plugins/bp-user-reviews/js/bp-user-reviews-admin.jsbp-user-reviews/css/bp-user-reviews.css?ver=bp-user-reviews/css/bp-user-reviews-admin.css?ver=bp-user-reviews/js/bp-user-reviews.js?ver=bp-user-reviews/js/bp-user-reviews-admin.js?ver=HTML / DOM Fingerprints
bp-user-reviewsbp-user-reviews-adminbp-user-reviews-rating-starsbp-user-reviews-review-itembp-user-reviews-admin-columndata-averagedata-starsbp_user_reviews_ajax_urlbp_user_reviews_settings