Custom Profile Filters for BuddyPress Security & Risk Analysis

wordpress.org/plugins/buddypress-custom-profile-filters

Allows users to take control of the way that the links in their Buddypress profiles are handled.

10 active installs v1.1 PHP + WP 2.5+ Updated Apr 8, 2013
bbcodebuddypressfilterprofileshortcode
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom Profile Filters for BuddyPress Safe to Use in 2026?

Generally Safe

Score 85/100

Custom Profile Filters for BuddyPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The security analysis of the buddypress-custom-profile-filters plugin version 1.1 indicates an exceptionally strong security posture based on the provided static analysis and vulnerability history. The plugin demonstrates a commendable adherence to secure coding practices, with no identified dangerous functions, raw SQL queries, or unescaped output. The absence of any file operations or external HTTP requests further minimizes the attack surface. Furthermore, the complete lack of known vulnerabilities, both historical and current, suggests a well-maintained and secure codebase.

The static analysis reveals a remarkably small attack surface, with zero identified entry points, including AJAX handlers, REST API routes, shortcodes, and cron events. This is a significant positive indicator. The taint analysis also shows no identified flows with unsanitized paths, reinforcing the conclusion of a secure design. The plugin's vulnerability history is equally impressive, with no recorded CVEs of any severity, suggesting a history of robust security.

While the plugin exhibits excellent security practices, the absolute absence of nonce checks and capability checks is a potential area for scrutiny. Although the current analysis shows no vulnerabilities stemming from this, future updates or unforeseen interactions could potentially expose the plugin if these crucial security mechanisms are not incorporated. Overall, this plugin presents a highly secure profile, with its strengths far outweighing any potential, albeit currently theoretical, weaknesses.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Custom Profile Filters for BuddyPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Custom Profile Filters for BuddyPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Custom Profile Filters for BuddyPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterbp_get_the_profile_field_valuebuddypress-custom-profile-filters-bp-functions.php:18
filterbp_get_the_profile_field_valuebuddypress-custom-profile-filters-bp-functions.php:37
filterbp_get_the_profile_field_valuebuddypress-custom-profile-filters-bp-functions.php:47
actionbp_initbuddypress-custom-profile-filters.php:32
Maintenance & Trust

Custom Profile Filters for BuddyPress Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedApr 8, 2013
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Custom Profile Filters for BuddyPress Developer Profile

antonchanning

3 plugins · 120 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom Profile Filters for BuddyPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/buddypress-custom-profile-filters/

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Custom Profile Filters for BuddyPress