
BuddyPress Activity Stream Hashtags Security & Risk Analysis
wordpress.org/plugins/buddypress-activity-stream-hashtagsThis plugin will convert #hashtags references to a link (activity search page) posted within the activity stream
Is BuddyPress Activity Stream Hashtags Safe to Use in 2026?
Generally Safe
Score 85/100BuddyPress Activity Stream Hashtags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the "buddypress-activity-stream-hashtags" plugin v0.5.1 appears to be relatively good based on the static analysis and vulnerability history. There are no identified dangerous functions, raw SQL queries, file operations, or external HTTP requests, which are common sources of vulnerabilities. The plugin also utilizes prepared statements for its SQL queries and has a nonce check, indicating some good security practices are in place.
However, a significant concern is the low percentage (35%) of properly escaped outputs. This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities, where unsanitized data might be displayed to users. While the attack surface is reported as zero in terms of AJAX handlers, REST API routes, and shortcodes, this could be a limitation of the static analysis tool or indicate a very minimal plugin functionality. The absence of capability checks on any entry points (though there are none detected) is also a weakness. The complete lack of recorded vulnerabilities in its history is positive but doesn't negate the risks identified in the code itself.
In conclusion, while the plugin avoids many common pitfalls like raw SQL and dangerous functions, the significant risk of unescaped output warrants attention. The limited attack surface reported might also be an area to investigate further if the plugin performs any user-facing actions. Overall, the plugin has a decent foundation but requires improvement in output sanitization to mitigate potential XSS risks.
Key Concerns
- Insufficient output escaping (35% proper)
- Missing capability checks on potential entry points
BuddyPress Activity Stream Hashtags Security Vulnerabilities
BuddyPress Activity Stream Hashtags Release Timeline
BuddyPress Activity Stream Hashtags Code Analysis
Output Escaping
BuddyPress Activity Stream Hashtags Attack Surface
WordPress Hooks 18
Maintenance & Trust
BuddyPress Activity Stream Hashtags Maintenance & Trust
Maintenance Signals
Community Trust
BuddyPress Activity Stream Hashtags Alternatives
HashBuddy
hashbuddy
Hashtags for WordPress, BuddyPress and bbPress. Adds hashtag links to BuddyPress activity and bbPress topics. Hashtags turn into links that are used t …
Activity Plus Reloaded for BuddyPress
bp-activity-plus-reloaded
Note: This plugin will be discontinued by March 31st, 2025 in favor of BuddyPress Attachment plugin. Please migrate to the new plugin before that date …
BuddyKit – Additional features for BuddyPress
buddykit
BuddyKit adds several features like Live Notifications and Media Activities to your BuddyPress powered websites.
BuddyPress Edit Activity Stream
buddypress-edit-activity-stream
This plugin allows an user to edit their activity stream status update within a specified time period.
Buddypress Activity Plus Styling
bp-activity-plus-styling
Additional CSS styles for the Buddypress Activity Plus plugin.
BuddyPress Activity Stream Hashtags Developer Profile
12 plugins · 240 total installs
How We Detect BuddyPress Activity Stream Hashtags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buddypress-activity-stream-hashtags/bp-activity-hashtags.css/wp-content/plugins/buddypress-activity-stream-hashtags/bp-activity-hashtags.jsbuddypress-activity-stream-hashtags/bp-activity-hashtags.css?ver=buddypress-activity-stream-hashtags/bp-activity-hashtags.js?ver=HTML / DOM Fingerprints
bp-activity-hashtags-filterdata-tagwindow.etivite_bp_activity_hashtags_filter_init