
BuddyPress Custom Posts Security & Risk Analysis
wordpress.org/plugins/buddypress-custom-postsProvides an API to create custom components in BuddyPress around custom post types in WordPress. This plugin is meant to be used by developers to map …
Is BuddyPress Custom Posts Safe to Use in 2026?
Generally Safe
Score 85/100BuddyPress Custom Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The buddypress-custom-posts plugin v0.1.2.5 presents a generally positive security posture, with no known CVEs and robust use of nonces and capability checks. The static analysis reveals no identified dangerous functions, file operations, or external HTTP requests, which are significant strengths. The absence of any attack surface (AJAX, REST API, shortcodes, cron events) is particularly noteworthy and suggests a limited potential for external exploitation through these common WordPress entry points.
However, concerns arise from the output escaping and SQL query practices. A mere 16% of output appears to be properly escaped, indicating a substantial risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is rendered without proper sanitization. Additionally, 50% of SQL queries are not using prepared statements, which opens the door to SQL injection vulnerabilities. While the taint analysis shows no critical or high-severity unsanitized flows, the identified flow with an unsanitized path, combined with the poor output escaping and raw SQL, warrants attention.
In conclusion, the plugin benefits from a lack of known vulnerabilities and a small attack surface. The strong emphasis on nonces and capability checks is commendable. The primary weaknesses lie in the insufficient output escaping and the use of unprepared SQL queries, creating potential for XSS and SQL injection. Addressing these specific code-level issues should be the priority for improving the plugin's security.
Key Concerns
- Low percentage of properly escaped output
- 50% of SQL queries use raw SQL
- Taint flow with unsanitized path
BuddyPress Custom Posts Security Vulnerabilities
BuddyPress Custom Posts Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
BuddyPress Custom Posts Attack Surface
WordPress Hooks 28
Maintenance & Trust
BuddyPress Custom Posts Maintenance & Trust
Maintenance Signals
Community Trust
BuddyPress Custom Posts Alternatives
Duplicate Page
duplicate-page
Duplicate Posts, Pages and Custom Posts easily using single click
Duplicate Page and Post
duplicate-wp-page-post
Duplicate post, Duplicate page and Duplicate custom post or clone page and clone post.
CMS Tree Page View
cms-tree-page-view
Adds a tree view of all pages & custom posts. Get a great overview + options to drag & drop to reorder & option to add multiple pages.
Better Messages – Live Chat, Chat Rooms, Real-Time Messaging & Private Messages
bp-better-messages
Real-time messaging and chat rooms for WordPress ecosystem: private conversations, public and private chat rooms, video & audio calls, and more.
rtMedia for WordPress, BuddyPress and bbPress
buddypress-media
Add albums, photo, audio/video upload, privacy, sharing, front-end uploads & more. All this works on mobile/tablets devices.
BuddyPress Custom Posts Developer Profile
2 plugins · 210 total installs
How We Detect BuddyPress Custom Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buddypress-custom-posts/themes/type/assets/css/edit.css