
BuddyPress Community Stats Security & Risk Analysis
wordpress.org/plugins/buddypress-community-statsThis plugin will display your buddypress community total counts for members, status updates, group forums topics, posts(bbPress 1.
Is BuddyPress Community Stats Safe to Use in 2026?
Generally Safe
Score 85/100BuddyPress Community Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Buddypress Community Stats plugin v0.5.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by having a minimal attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without proper authentication or permission checks. Furthermore, the absence of external HTTP requests and file operations reduces the potential for certain types of remote code execution and data leakage. The presence of a nonce check and a generally low number of SQL queries, with a good percentage using prepared statements, are also encouraging signs.
However, significant concerns arise from the static code analysis. The use of the `create_function()` is a clear indicator of a potentially dangerous coding practice that can be exploited. More critically, the analysis reveals that 0% of the total 22 output operations are properly escaped. This is a substantial security risk, as it opens the door to Cross-Site Scripting (XSS) vulnerabilities, where user-supplied input could be rendered directly in the browser, allowing for malicious script execution. The taint analysis, while showing no critical or high severity flows with unsanitized paths, does not negate the XSS risk identified by the lack of output escaping.
The plugin's vulnerability history is remarkably clean, with no known CVEs. This absence of past vulnerabilities might suggest a history of careful development or a lack of prior scrutiny. However, it is crucial not to solely rely on this history, especially given the identified coding issues in the current version. The plugin's strengths lie in its limited attack surface and control over external interactions, but the lack of output escaping and the use of `create_function()` present clear and exploitable risks that need immediate attention.
Key Concerns
- Use of dangerous function create_function()
- 0% of outputs properly escaped
BuddyPress Community Stats Security Vulnerabilities
BuddyPress Community Stats Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
BuddyPress Community Stats Attack Surface
WordPress Hooks 16
Maintenance & Trust
BuddyPress Community Stats Maintenance & Trust
Maintenance Signals
Community Trust
BuddyPress Community Stats Alternatives
BuddyPress Member Profile Stats
buddypress-member-profile-stats
This plugin will display a member since and a few simple count totals for status, topics, posts, blog comments along with a per day average.
Better Messages – Live Chat, Chat Rooms, Real-Time Messaging & Private Messages
bp-better-messages
Real-time messaging and chat rooms for WordPress ecosystem: private conversations, public and private chat rooms, video & audio calls, and more.
BP Profile Search
bp-profile-search
Member search and member directories for BuddyPress and the BuddyBoss Platform.
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress
youzify
The best BuddyPress plugin for building online communities, user profile, social networks, and membership sites on WordPress with tons of features.
BuddyPress Members Only
buddypress-members-only
BuddyPress Members Only restricts Your Buddypress and Wordpress to logged in/registered members.
BuddyPress Community Stats Developer Profile
10 plugins · 200 total installs
How We Detect BuddyPress Community Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buddypress-community-stats/bp-community-stats.css/wp-content/plugins/buddypress-community-stats/js/bp-community-stats.js/wp-content/plugins/buddypress-community-stats/js/bp-community-stats.jsbuddypress-community-stats/bp-community-stats.css?ver=buddypress-community-stats/js/bp-community-stats.js?ver=HTML / DOM Fingerprints
bp-community-stats-footercommunity-countetivite_bp_community_stats[bp_community_stats_members][bp_community_stats_active][bp_community_stats_status][bp_community_stats_groups]