
Buddy Progress Bar Security & Risk Analysis
wordpress.org/plugins/buddy-progress-barA BuddyPress plugin that use a point system to display a progress bar or progress percentage for any of completed member's xprofile fields and/or …
Is Buddy Progress Bar Safe to Use in 2026?
Generally Safe
Score 85/100Buddy Progress Bar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "buddy-progress-bar" plugin, in version 1.0.3, exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for its SQL queries and has no recorded history of known vulnerabilities (CVEs). This suggests a generally stable and secure development process for past issues. However, the static analysis reveals significant areas of concern. The presence of the `create_function` function, a known deprecated and potentially dangerous PHP function, introduces a risk. Furthermore, a substantial portion (72%) of its output is not properly escaped, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of any capability checks, nonce checks, or any protection on its identified entry points (though the current number is zero) is also worrying, as any future expansion of the attack surface could be immediately vulnerable.
Key Concerns
- Use of dangerous function: create_function
- High percentage of unescaped output
- Missing nonce checks
- Missing capability checks
Buddy Progress Bar Security Vulnerabilities
Buddy Progress Bar Code Analysis
Dangerous Functions Found
Output Escaping
Buddy Progress Bar Attack Surface
WordPress Hooks 23
Maintenance & Trust
Buddy Progress Bar Maintenance & Trust
Maintenance Signals
Community Trust
Buddy Progress Bar Alternatives
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress
youzify
The best BuddyPress plugin for building online communities, user profile, social networks, and membership sites on WordPress with tons of features.
BuddyPress Xprofile Custom Field Types
bp-xprofile-custom-field-types
Buddypress Xprofile Custom Field Types adds extra custom profile fields to BuddyPress. Field types are: Birthdate, Email, Url etc.
JSON API User
json-api-user
Extends the JSON API Plugin to allow RESTful user registration, authentication & many other User Meta, BP functions. A Pro version is also available.
BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages
wc4bp
Integrate WooCommerce my account into BuddyPress member profiles. Bring your WooCommerce member pages into BuddyPress and BuddyBoss.
BuddyPress Edit Activity
buddypress-edit-activity
BuddyPress Edit Activity allows your members to edit their activity posts on the front-end of your BuddyPress-powered site.
Buddy Progress Bar Developer Profile
1 plugin · 20 total installs
How We Detect Buddy Progress Bar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buddy-progress-bar/css/progress-bar.cssbuddy-progress-bar/css/progress-bar.css?ver=