BuddyPress Activity Stream AtGroups Security & Risk Analysis

wordpress.org/plugins/buddypress-activity-stream-atgroups

This plugin will link @(group_slug) syntax to group home page and/or use =(group_slug) to post an update to group

10 active installs v0.1.0 PHP + WP + Updated Dec 5, 2011
activityactivity-streambuddypressgroups
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BuddyPress Activity Stream AtGroups Safe to Use in 2026?

Generally Safe

Score 85/100

BuddyPress Activity Stream AtGroups has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The "buddypress-activity-stream-atgroups" plugin version 0.1.0 demonstrates a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with open attack surfaces is commendable. Furthermore, the code signals indicate a rigorous approach to security, with no dangerous functions detected, all SQL queries using prepared statements, and all output properly escaped. The lack of file operations, external HTTP requests, and no recorded vulnerability history further bolster its security. This suggests the plugin authors have implemented good security practices.

However, the analysis also highlights a significant area of concern: the complete lack of any capability checks or nonce checks. While the current version may not expose vulnerabilities due to its limited attack surface, this absence means that if any new entry points are introduced in future versions without proper authentication and authorization, they could be easily exploited. The taint analysis showing zero flows is positive, but this is likely a consequence of the minimal attack surface rather than inherent sanitization for complex data flows. The plugin's strengths lie in its initial design and adherence to basic secure coding principles for its current features, but the lack of fundamental security checks on potential interactions is a notable weakness.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

BuddyPress Activity Stream AtGroups Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BuddyPress Activity Stream AtGroups Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

BuddyPress Activity Stream AtGroups Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
filterbp_activity_before_savebp-activity-atgroups-loader.php:31
filterbp_activity_after_savebp-activity-atgroups-loader.php:34
filterpre_comment_contentbp-activity-atgroups-loader.php:35
filtergroup_forum_topic_text_before_savebp-activity-atgroups-loader.php:36
filtergroup_forum_post_text_before_savebp-activity-atgroups-loader.php:37
filterbp_get_activity_content_bodybp-activity-atgroups-loader.php:38
actionbp_includebp-activity-atgroups-loader.php:44
filterplugin_action_linksbp-activity-atgroups-loader.php:84
Maintenance & Trust

BuddyPress Activity Stream AtGroups Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedDec 5, 2011
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

BuddyPress Activity Stream AtGroups Developer Profile

rich

4 plugins · 40 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BuddyPress Activity Stream AtGroups

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/buddypress-activity-stream-atgroups/bp-activity-atgroups.php/wp-content/plugins/buddypress-activity-stream-atgroups/bp-activity-atgroups-loader.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about BuddyPress Activity Stream AtGroups