
BP XProfile Range Field Security & Risk Analysis
wordpress.org/plugins/bp-xprofile-range-fieldThis plugin will add range field types to Buddypress Xprofile Fields.
Is BP XProfile Range Field Safe to Use in 2026?
Generally Safe
Score 85/100BP XProfile Range Field has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bp-xprofile-range-field" plugin v1.2.1 exhibits a very strong security posture based on the provided static analysis and vulnerability history. There are no identified entry points like AJAX handlers, REST API routes, or shortcodes, significantly reducing the attack surface. Furthermore, the code signals show responsible development practices, with no dangerous functions, all SQL queries using prepared statements, and a high percentage of output escaping. The absence of file operations and external HTTP requests further bolsters its security. The lack of any recorded vulnerabilities or CVEs in its history is a testament to its stability and secure coding.
While the plugin demonstrates excellent security hygiene, the complete absence of nonces and capability checks across its (albeit non-existent) entry points could be a theoretical concern in scenarios where these elements might be introduced in future updates without careful consideration. However, given the current structure and the explicit mention of zero entry points, this is a low-risk observation. The taint analysis also shows no identified vulnerabilities, reinforcing the positive security assessment. Overall, this plugin appears to be developed with security as a high priority, making it a very safe choice.
Key Concerns
- No nonce checks present
- No capability checks present
BP XProfile Range Field Security Vulnerabilities
BP XProfile Range Field Release Timeline
BP XProfile Range Field Code Analysis
Output Escaping
BP XProfile Range Field Attack Surface
WordPress Hooks 8
Maintenance & Trust
BP XProfile Range Field Maintenance & Trust
Maintenance Signals
Community Trust
BP XProfile Range Field Alternatives
BuddyPress Xprofile Custom Field Types
bp-xprofile-custom-field-types
Buddypress Xprofile Custom Field Types adds extra custom profile fields to BuddyPress. Field types are: Birthdate, Email, Url etc.
JSON API User
json-api-user
Extends the JSON API Plugin to allow RESTful user registration, authentication & many other User Meta, BP functions. A Pro version is also available.
BuddyPress XProfile Custom Image Field
buddypress-xprofile-image-field
With the BPXPIF plugin you can add XProfile fields of type Image without writing any custom code.
BuddyPress to WordPress Full Sync
bp2wp-full-sync
BuddyPress to WordPress Full Sync lets BuddyPress xProfile fields to synchronize with WordPress user fields
LH Buddypress Export Xprofile Data
lh-buddypress-export-xprofile-data
This plugin lets you export xprofile field data from BuddyPress, as CSV, for manipulation elsewhere..
BP XProfile Range Field Developer Profile
1 plugin · 10 total installs
How We Detect BP XProfile Range Field
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bp-xprofile-range-field/js/admin.js/wp-content/plugins/bp-xprofile-range-field/js/public.js/wp-content/plugins/bp-xprofile-range-field/js/admin.js/wp-content/plugins/bp-xprofile-range-field/js/public.jsbp-xprofile-range-field/js/admin.js?ver=bp-xprofile-range-field/js/public.js?ver=HTML / DOM Fingerprints
fields_type_with_select