BuddyCommerce: WooCommerce and BuddyPress Integration Security & Risk Analysis

wordpress.org/plugins/buddycommerce

Highly Flexible WooCommerce to BuddyPress integration which puts site admins in the complete control.

900 active installs v1.0.8 PHP 5.4+ WP 5.0+ Updated Aug 4, 2025
buddypresswoocommercewoocommerce-for-buddypress
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BuddyCommerce: WooCommerce and BuddyPress Integration Safe to Use in 2026?

Generally Safe

Score 100/100

BuddyCommerce: WooCommerce and BuddyPress Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The static analysis of Buddycommerce v1.0.8 reveals a generally strong security posture. The plugin exhibits good practices by having no critical or high-severity taint flows, no raw SQL queries, and a high percentage of properly escaped output. The presence of nonce and capability checks on its single AJAX handler is also a positive indicator of secure coding. However, the absence of any recorded vulnerabilities in its history, while seemingly positive, could also indicate a lack of thorough security auditing or a relatively new plugin with limited exposure. The limited attack surface and the absence of dangerous functions further contribute to a good initial impression. Overall, Buddycommerce v1.0.8 appears to be a securely coded plugin, with its primary strength lying in its robust input validation and output sanitization measures, although its vulnerability history is sparse.

Key Concerns

  • High percentage of unescaped output
  • Limited vulnerability history may indicate lack of auditing
Vulnerabilities
None known

BuddyCommerce: WooCommerce and BuddyPress Integration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BuddyCommerce: WooCommerce and BuddyPress Integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
71 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

85% escaped84 total outputs
Attack Surface

BuddyCommerce: WooCommerce and BuddyPress Integration Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_pt_settings_create_pagesrc\admin\pt-settings\src\class-ajax-handler.php:31
WordPress Hooks 46
actionadmin_initsrc\admin\class-admin-settings-helper.php:57
actionadmin_menusrc\admin\class-admin-settings-helper.php:58
actionadmin_enqueue_scriptssrc\admin\pt-settings\pt-settings-loader.php:89
actionplugins_loadedsrc\bootstrap\class-bc-bootstrapper.php:84
actionplugins_loadedsrc\bootstrap\class-bc-bootstrapper.php:85
actioninitsrc\bootstrap\class-bc-bootstrapper.php:87
actionwp_enqueue_scriptssrc\bootstrap\class-bc-bootstrapper.php:90
actionbp_template_contentsrc\core\users\class-bc-screens.php:53
actionbp_template_contentsrc\core\users\class-bc-screens.php:62
actionbp_template_contentsrc\core\users\class-bc-screens.php:70
actionbp_template_contentsrc\core\users\class-bc-screens.php:78
actionbp_template_contentsrc\core\users\class-bc-screens.php:91
actionbp_template_contentsrc\core\users\class-bc-screens.php:104
actionbp_template_contentsrc\core\users\class-bc-screens.php:112
actionbp_template_contentsrc\core\users\class-bc-screens.php:123
actionbp_template_contentsrc\core\users\class-bc-screens.php:132
actionbp_template_contentsrc\core\users\class-bc-screens.php:147
actionbp_template_contentsrc\core\users\class-bc-screens.php:156
actionbp_template_contentsrc\core\users\class-bc-screens.php:171
filterwoocommerce_is_account_pagesrc\core\users\filters\class-bc-condition-filters.php:46
filterwoocommerce_is_order_received_pagesrc\core\users\filters\class-bc-condition-filters.php:48
filterpage_linksrc\core\users\filters\class-bc-url-filters.php:45
filterwoocommerce_get_myaccount_page_permalinksrc\core\users\filters\class-bc-url-filters.php:48
filterwoocommerce_get_cart_page_permalinksrc\core\users\filters\class-bc-url-filters.php:50
filterwoocommerce_get_checkout_page_permalinksrc\core\users\filters\class-bc-url-filters.php:52
filterwoocommerce_get_endpoint_urlsrc\core\users\filters\class-bc-url-filters.php:60
filterwoocommerce_get_view_order_urlsrc\core\users\filters\class-bc-url-filters.php:62
filterwcs_get_view_subscription_urlsrc\core\users\filters\class-bc-url-filters.php:74
filterwc_memberships_members_area_navigation_itemssrc\core\users\filters\class-bc-url-filters.php:77
actionwpsrc\core\users\handlers\class-bc-add-payment-methods-screen-handler.php:46
actionbp_actionssrc\core\users\handlers\class-bc-address-screen-handler.php:46
actionbp_actionssrc\core\users\handlers\class-bc-checkout-endpoint-screen-handler.php:46
actionbp_actionssrc\core\users\handlers\class-bc-membership-endpoint-screen-handler.php:46
actionbp_actionssrc\core\users\handlers\class-bc-paginated-views-handler.php:48
actionbp_setup_navsrc\core\users\handlers\class-bc-tabs-helper.php:50
actionbp_setup_admin_barsrc\core\users\handlers\class-bc-tabs-helper.php:56
actionbp_actionssrc\core\users\handlers\class-bc-view-order-screen-handler.php:46
actionbp_actionssrc\core\users\handlers\class-bc-view-subscription-screen-handler.php:46
filterbp_template_redirectsrc\core\users\redirects\class-bc-account-redirects.php:46
filterbp_template_redirectsrc\core\users\redirects\class-bc-account-redirects.php:47
filterbp_template_redirectsrc\core\users\redirects\class-bc-account-redirects.php:48
filterbp_template_redirectsrc\core\users\redirects\class-bc-account-redirects.php:49
filterbp_template_redirectsrc\core\users\redirects\class-bc-account-redirects.php:50
filterbp_template_redirectsrc\core\users\redirects\class-bc-account-redirects.php:51
filterbp_template_redirectsrc\core\users\redirects\class-bc-account-redirects.php:52
actionbp_template_redirectsrc\core\users\redirects\class-bc-account-redirects.php:55
Maintenance & Trust

BuddyCommerce: WooCommerce and BuddyPress Integration Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 4, 2025
PHP min version5.4
Downloads40K

Community Trust

Rating100/100
Number of ratings5
Active installs900
Developer Profile

BuddyCommerce: WooCommerce and BuddyPress Integration Developer Profile

BuddyDev

14 plugins · 16K total installs

92
trust score
Avg Security Score
88/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect BuddyCommerce: WooCommerce and BuddyPress Integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/buddycommerce/assets/buddycommerce-core.css
Script Paths
/wp-content/plugins/buddycommerce/src/admin/pt-settings/js/pt-settings-media-uploader.js/wp-content/plugins/buddycommerce/src/admin/pt-settings/js/pt-settings-page-create.js
Version Parameters
buddycommerce-core?ver=

HTML / DOM Fingerprints

CSS Classes
pt-settings-image-placeholderpt-settings-image-action-visiblept-settings-delete-imagept-settings-hidden-image-urlpt-settings-upload-image-buttonpt-settings-field-descriptionpt-settings-create-page-buttonpt-settings-create-page-status+1 more
HTML Comments
<!-- Used for Image field type --><!-- Used for Image field type --><!-- Used for Image field type --><!-- Image Upload Field class -->+10 more
Data Attributes
data-iddata-btn-titledata-uploader-titledata-actiondata-keydata-nonce
JS Globals
ptSettingsMediaUploaderptSettingsPageCreate
FAQ

Frequently Asked Questions about BuddyCommerce: WooCommerce and BuddyPress Integration