BP XProfile Range Field Security & Risk Analysis

wordpress.org/plugins/bp-xprofile-range-field

This plugin will add range field types to Buddypress Xprofile Fields.

10 active installs v1.2.1 PHP + WP 3.0.1+ Updated Feb 19, 2017
buddypressrange-fieldsxprofile
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BP XProfile Range Field Safe to Use in 2026?

Generally Safe

Score 85/100

BP XProfile Range Field has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "bp-xprofile-range-field" plugin v1.2.1 exhibits a very strong security posture based on the provided static analysis and vulnerability history. There are no identified entry points like AJAX handlers, REST API routes, or shortcodes, significantly reducing the attack surface. Furthermore, the code signals show responsible development practices, with no dangerous functions, all SQL queries using prepared statements, and a high percentage of output escaping. The absence of file operations and external HTTP requests further bolsters its security. The lack of any recorded vulnerabilities or CVEs in its history is a testament to its stability and secure coding.

While the plugin demonstrates excellent security hygiene, the complete absence of nonces and capability checks across its (albeit non-existent) entry points could be a theoretical concern in scenarios where these elements might be introduced in future updates without careful consideration. However, given the current structure and the explicit mention of zero entry points, this is a low-risk observation. The taint analysis also shows no identified vulnerabilities, reinforcing the positive security assessment. Overall, this plugin appears to be developed with security as a high priority, making it a very safe choice.

Key Concerns

  • No nonce checks present
  • No capability checks present
Vulnerabilities
None known

BP XProfile Range Field Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

BP XProfile Range Field Release Timeline

v1.2.1Current
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

BP XProfile Range Field Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
18 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

72% escaped25 total outputs
Attack Surface

BP XProfile Range Field Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionplugins_loadedindex.php:21
actionadmin_initindex.php:22
actionadmin_noticesindex.php:23
actionbp_initindex.php:24
filterbp_field_validation_typeindex.php:25
filterbp_field_type_for_queryindex.php:26
filterbp_field_type_for_search_formindex.php:27
filterbp_xprofile_get_field_typesindex.php:28
Maintenance & Trust

BP XProfile Range Field Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedFeb 19, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

BP XProfile Range Field Developer Profile

Askary Abbas

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BP XProfile Range Field

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bp-xprofile-range-field/js/admin.js/wp-content/plugins/bp-xprofile-range-field/js/public.js
Script Paths
/wp-content/plugins/bp-xprofile-range-field/js/admin.js/wp-content/plugins/bp-xprofile-range-field/js/public.js
Version Parameters
bp-xprofile-range-field/js/admin.js?ver=bp-xprofile-range-field/js/public.js?ver=

HTML / DOM Fingerprints

JS Globals
fields_type_with_select
FAQ

Frequently Asked Questions about BP XProfile Range Field