
BuddyMenu BuddyLinks Security & Risk Analysis
wordpress.org/plugins/buddymenu-buddylinksBuddyPress BuddyLinks does three things really well:
Is BuddyMenu BuddyLinks Safe to Use in 2026?
Generally Safe
Score 85/100BuddyMenu BuddyLinks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "buddymenu-buddylinks" v2.2.0 plugin presents a mixed security posture. On the positive side, there are no known CVEs, and all SQL queries are properly prepared, indicating good practices in database interaction. The absence of file operations and external HTTP requests further reduces the attack surface in these areas. However, the code analysis reveals significant concerns, most notably the presence of the `create_function` dangerous function, which can lead to code injection if not handled with extreme care. Additionally, a concerning 67% of output escaping is not properly handled, leaving the plugin vulnerable to Cross-Site Scripting (XSS) attacks. The lack of nonce and capability checks on entry points, despite a small attack surface, means that any unauthenticated user could potentially trigger actions or view sensitive information if vulnerabilities existed within the shortcodes.
The vulnerability history is currently clean, which is a positive indicator. However, this does not negate the risks identified in the static code analysis. The combination of a dangerous function and widespread unescaped output, coupled with a lack of robust authorization checks on its limited entry points, suggests a potential for exploitation. While the plugin currently has no known vulnerabilities, the underlying code quality and implementation details present a risk that could be exploited by attackers if not addressed.
Key Concerns
- Presence of dangerous function `create_function`
- High percentage of unescaped output
- No nonce checks on entry points
- No capability checks on entry points
BuddyMenu BuddyLinks Security Vulnerabilities
BuddyMenu BuddyLinks Code Analysis
Dangerous Functions Found
Output Escaping
BuddyMenu BuddyLinks Attack Surface
Shortcodes 2
WordPress Hooks 2
Maintenance & Trust
BuddyMenu BuddyLinks Maintenance & Trust
Maintenance Signals
Community Trust
BuddyMenu BuddyLinks Alternatives
Broken Link Checker
broken-link-checker
Broken Link Checker helps you catch broken links & images fast, before they hurt your SEO or UX. Scan and bulk-fix issues from one easy dashboard.
Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links
broken-link-checker-seo
Broken Link Checker by AIOSEO ensures all links on your website are working. Check your site for broken links and easily fix them to improve SEO.
PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin
pretty-link
🌠 The best WordPress link management, branding, tracking, sharing and payments plugin. Easily make pretty & trackable shortlinks. 🔗
LuckyWP Table of Contents
luckywp-table-of-contents
Creates SEO-friendly table of contents for your posts/pages. Works automatically or manually (via shortcode, Gutenberg block or widget).
Nginx Helper
nginx-helper
Cleans nginx's fastcgi/proxy cache or redis-cache whenever a post is edited/published. Also does a few more things.
BuddyMenu BuddyLinks Developer Profile
2 plugins · 70 total installs
How We Detect BuddyMenu BuddyLinks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buddymenu-buddylinks/buddymenu-style.cssbuddymenu-style.css?ver=20130328HTML / DOM Fingerprints
widget_text