Buddypress Activity Anywhere Security & Risk Analysis

wordpress.org/plugins/buddypress-activity-anywhere

Let the members of your site post an update to their activity stream from anywhere in your site or any other subsite in a multisite installation inste …

10 active installs v1.1 PHP + WP 3.8+ Updated Apr 11, 2014
activitybuddypresspost
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Buddypress Activity Anywhere Safe to Use in 2026?

Generally Safe

Score 85/100

Buddypress Activity Anywhere has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The plugin "buddypress-activity-anywhere" v1.1 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the analysis indicates a lack of dangerous functions and file operations, and all SQL queries utilize prepared statements, which are excellent security practices. The presence of a nonce check is also a positive indicator.

However, a critical concern arises from the complete lack of output escaping. With 100% of outputs not properly escaped, this presents a significant risk for Cross-Site Scripting (XSS) vulnerabilities. If any user-supplied data is ever displayed on the front-end without proper sanitization or escaping, an attacker could inject malicious scripts. The zero taint analysis flows might be misleading if the taint analysis itself was not comprehensive or if the limited entry points did not expose exploitable data flows.

The plugin's vulnerability history is clean, with no known CVEs. This, combined with the limited attack surface, suggests a history of secure development or a lack of targeting. However, the current lack of output escaping overshadows this positive history and needs immediate attention. The plugin has strong foundations in input handling and SQL querying, but a critical weakness in output sanitization leaves it vulnerable.

Key Concerns

  • All outputs are unescaped
Vulnerabilities
None known

Buddypress Activity Anywhere Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Buddypress Activity Anywhere Release Timeline

v1.1Current
v1.0
Code Analysis
Analyzed Mar 17, 2026

Buddypress Activity Anywhere Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
0 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped4 total outputs
Attack Surface

Buddypress Activity Anywhere Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionwp_enqueue_scriptsbp-activity-anywhere.php:63
actionadmin_bar_menubp-activity-anywhere.php:64
actionwp_footerbp-activity-anywhere.php:65
actionbp_initbp-activity-anywhere.php:149
actionadmin_menuincludes\bpqa-admin.php:18
actionadmin_initincludes\bpqa-admin.php:41
actionadmin_initincludes\bpqa-admin.php:118
Maintenance & Trust

Buddypress Activity Anywhere Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedApr 11, 2014
PHP min version
Downloads3K

Community Trust

Rating70/100
Number of ratings2
Active installs10
Developer Profile

Buddypress Activity Anywhere Developer Profile

Eyal Fitoussi

4 plugins · 4K total installs

78
trust score
Avg Security Score
85/100
Avg Patch Time
31 days
View full developer profile
Detection Fingerprints

How We Detect Buddypress Activity Anywhere

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/buddypress-activity-anywhere/form-templates/default/css/style.css/wp-content/plugins/buddypress-activity-anywhere/assets/js/js.js
Script Paths
/wp-content/plugins/buddypress-activity-anywhere/assets/js/js.js
Version Parameters
buddypress-activity-anywhere/assets/js/js.js?ver=

HTML / DOM Fingerprints

CSS Classes
bpqa-form-trigger
Data Attributes
data-bpqa-textarea
JS Globals
BPQA_URLBPQA_PATHBPQA_VERSION
FAQ

Frequently Asked Questions about Buddypress Activity Anywhere