
BP User Widgets Security & Risk Analysis
wordpress.org/plugins/bp-user-widgetsAdd user editable widgets to profile pages with a widgets for text, video, buddypress friends and groups, as well as followed and followiing.
Is BP User Widgets Safe to Use in 2026?
Generally Safe
Score 100/100BP User Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The bp-user-widgets plugin, version 1.0.8, demonstrates a generally good security posture with no known vulnerabilities in its history and strong adherence to several security best practices. The plugin has no recorded CVEs, indicating a history of stable security. Static analysis reveals a complete absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests, all positive signs. The presence of nonce checks on all AJAX handlers and capability checks on a significant portion of its entry points further bolster its security. However, a notable concern arises from the taint analysis, which identified 3 flows with unsanitized paths, despite no critical or high severity issues being flagged. This suggests a potential for sensitive data to be mishandled if these flows were exploited in conjunction with other weaknesses, though the current lack of exploitable vulnerabilities is encouraging. The plugin's output escaping, while decent at 73%, still leaves room for improvement, as a portion of its output is not properly sanitized, posing a minor risk of cross-site scripting (XSS) if the unsanitized output contains user-supplied data. Overall, the plugin is relatively secure due to its robust foundation and lack of historical vulnerabilities, but the identified unsanitized paths and partially unescaped output warrant attention for future development.
Key Concerns
- Flows with unsanitized paths detected
- Output escaping is not 100%
BP User Widgets Security Vulnerabilities
BP User Widgets Code Analysis
Output Escaping
Data Flow Analysis
BP User Widgets Attack Surface
AJAX Handlers 8
WordPress Hooks 6
Maintenance & Trust
BP User Widgets Maintenance & Trust
Maintenance Signals
Community Trust
BP User Widgets Alternatives
BP Profile Home Widgets
bp-profile-home-widgets
Add user editable widgets to the BP Nouveau profile home page with a widgets for text, video, posts, BuddyPress activity, mentions, friends and groups …
One User Avatar | User Profile Picture
one-user-avatar
Use any image from your WordPress Media Library as a custom user avatar or user profile picture. Add your own Default Avatar.
bbPress Login Register Links On Forum Topic Pages
bbpress-login-register-links-on-forum-topic-pages
Add bbPress only sidebar, Add bbpress login link, bbpress register link, forget password link, log out link in bbpress forum index pages or bbpress si …
BuddyPress to WordPress Full Sync
bp2wp-full-sync
BuddyPress to WordPress Full Sync lets BuddyPress xProfile fields to synchronize with WordPress user fields
LH Buddypress Export Xprofile Data
lh-buddypress-export-xprofile-data
This plugin lets you export xprofile field data from BuddyPress, as CSV, for manipulation elsewhere..
BP User Widgets Developer Profile
20 plugins · 640 total installs
How We Detect BP User Widgets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bp-user-widgets/js/bpuw-fronntend.js/wp-content/plugins/bp-user-widgets/vendor/jquery/jquery-ui.css/wp-content/plugins/bp-user-widgets/css/bpuw.css/wp-content/plugins/bp-user-widgets/js/bpuw-fronntend.jsHTML / DOM Fingerprints
data-widget-iddata-widget-typebpuw_translateajax_object