
BuddyPress Activity Stream Extras Security & Risk Analysis
wordpress.org/plugins/buddypress-activity-stream-extrasA collection of small tweaks for the activity stream
Is BuddyPress Activity Stream Extras Safe to Use in 2026?
Generally Safe
Score 100/100BuddyPress Activity Stream Extras has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The WordPress plugin "buddypress-activity-stream-extras" v0.1.2 presents a mixed security posture. While the static analysis indicates a very small attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, and all SQL queries utilize prepared statements, there are significant concerns regarding output escaping. The fact that 0% of output is properly escaped is a critical weakness, potentially exposing the application to Cross-Site Scripting (XSS) vulnerabilities. The presence of a nonce check is a positive sign, but its effectiveness is undermined by the lack of capability checks, leaving entry points (if any were present) potentially vulnerable to unauthorized access if they were to be discovered or introduced in future versions. The plugin's vulnerability history is clean, with no recorded CVEs, which could indicate good development practices or simply a lack of rigorous security auditing or discovery of existing issues. However, the combination of a clean history and a small attack surface should not lead to complacency, especially given the critical output escaping issue. The current version demonstrates some security awareness with prepared statements and nonce checks but fails critically in output sanitization, representing a notable risk.
Key Concerns
- 0% output properly escaped
- 0 capability checks on entry points
BuddyPress Activity Stream Extras Security Vulnerabilities
BuddyPress Activity Stream Extras Code Analysis
SQL Query Safety
Output Escaping
BuddyPress Activity Stream Extras Attack Surface
WordPress Hooks 11
Maintenance & Trust
BuddyPress Activity Stream Extras Maintenance & Trust
Maintenance Signals
Community Trust
BuddyPress Activity Stream Extras Alternatives
Activity Plus Reloaded for BuddyPress
bp-activity-plus-reloaded
Note: This plugin will be discontinued by March 31st, 2025 in favor of BuddyPress Attachment plugin. Please migrate to the new plugin before that date …
BuddyKit – Additional features for BuddyPress
buddykit
BuddyKit adds several features like Live Notifications and Media Activities to your BuddyPress powered websites.
Buddypress Activity Plus Styling
bp-activity-plus-styling
Additional CSS styles for the Buddypress Activity Plus plugin.
BuddyPress Edit Activity Stream
buddypress-edit-activity-stream
This plugin allows an user to edit their activity stream status update within a specified time period.
BuddyPress Activity Stream Bump to Top
buddypress-activity-stream-bump-to-top
This plugin will "bump" an activity record to the top of the stream when activity comment reply is made.
BuddyPress Activity Stream Extras Developer Profile
4 plugins · 40 total installs
How We Detect BuddyPress Activity Stream Extras
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buddypress-activity-stream-extras/bp-activity-extras.php/wp-content/plugins/buddypress-activity-stream-extras/admin/bp-activity-extras-admin.php/wp-content/plugins/buddypress-activity-stream-extras/bp-activity-extras-loader.phpHTML / DOM Fingerprints
activity-extras-settings-formname="bp-activity-extras-settings-form"id="bp-activity-extras-settings-form"