BuddyPress Edit Activity Stream Security & Risk Analysis

wordpress.org/plugins/buddypress-edit-activity-stream

This plugin allows an user to edit their activity stream status update within a specified time period.

40 active installs v0.5.1 PHP + WP + Updated Oct 28, 2011
activity-streambuddypress
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BuddyPress Edit Activity Stream Safe to Use in 2026?

Generally Safe

Score 85/100

BuddyPress Edit Activity Stream has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The "buddypress-edit-activity-stream" plugin, version 0.5.1, exhibits a generally good security posture with no recorded vulnerabilities and a clean taint analysis. The static analysis reveals a very limited attack surface, with zero identified entry points that lack authentication checks. Furthermore, the code signals indicate the absence of dangerous functions, file operations, and external HTTP requests. SQL queries are exclusively handled with prepared statements, and there are a small number of nonce checks present, which is a positive indicator. However, a significant concern arises from the low percentage of properly escaped output (18%). This suggests a potential for cross-site scripting (XSS) vulnerabilities, as user-supplied data might be directly rendered without adequate sanitization. While the vulnerability history is clean, the unescaped output presents a latent risk that could be exploited if an attacker can inject malicious scripts into the activity stream.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

BuddyPress Edit Activity Stream Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BuddyPress Edit Activity Stream Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
2 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

18% escaped11 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
etivite_bp_edit_activity_admin (admin\bp-activity-edit-admin.php:3)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

BuddyPress Edit Activity Stream Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionbp_includebp-activity-edit-loader.php:24
filterplugin_action_linksbp-activity-edit-loader.php:56
actionbp_activity_entry_metabp-activity-edit.php:26
filterbody_classbp-activity-edit.php:116
actionwpbp-activity-edit.php:122
filterbp_located_templatebp-activity-edit.php:144
Maintenance & Trust

BuddyPress Edit Activity Stream Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedOct 28, 2011
PHP min version
Downloads10K

Community Trust

Rating74/100
Number of ratings3
Active installs40
Developer Profile

BuddyPress Edit Activity Stream Developer Profile

rich! @ etiviti

10 plugins · 200 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BuddyPress Edit Activity Stream

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
edit-activity
FAQ

Frequently Asked Questions about BuddyPress Edit Activity Stream