
BuddyPress Extended Friendship Request Security & Risk Analysis
wordpress.org/plugins/buddypress-extended-friendship-requestBuddyPress Extended Friendship Request plugin allows users to send a personalized message with the friendship requests.
Is BuddyPress Extended Friendship Request Safe to Use in 2026?
Generally Safe
Score 100/100BuddyPress Extended Friendship Request has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'buddypress-extended-friendship-request' v1.2.2 presents a mixed security posture. On the positive side, the static analysis reveals a small attack surface with no exposed REST API routes or shortcodes, and importantly, zero unprotected AJAX entry points. All SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are excellent security practices. The presence of nonce checks is also a good sign. However, a significant concern arises from the output escaping, where only 30% of the total outputs are properly escaped. This leaves a considerable portion of dynamic content vulnerable to being rendered without proper sanitization, potentially leading to cross-site scripting (XSS) vulnerabilities.
Key Concerns
- Low output escaping coverage
- Older vulnerability history, but XSS common
BuddyPress Extended Friendship Request Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
BuddyPress Extended Friendship Request < 1.0.2 - Cross-Site Scripting
BuddyPress Extended Friendship Request Code Analysis
Output Escaping
Data Flow Analysis
BuddyPress Extended Friendship Request Attack Surface
AJAX Handlers 2
WordPress Hooks 12
Maintenance & Trust
BuddyPress Extended Friendship Request Maintenance & Trust
Maintenance Signals
Community Trust
BuddyPress Extended Friendship Request Alternatives
Mutual Buddies
mutual-buddies
Mutual buddies displays BuddyPress mutual friends of the logged in user & the user whose profile the user is looking at on the Profile page.
Buddypress Friend of a Friend (FOAF)
buddypress-foaf
This plugin includes a new block inside each user profile page and includes a "Friend of a Friend (FOAF)" display.
BP Mutual Friends
bp-mutual-friends
List users' mutual friends in BuddyPress easily. One click install and setup.
Buddypress Friends
buddypress-friends
This plugin adds a widget to Buddypress that displays the friends for the current user that is logged in.
Personalized Activity for Buddypress – Friends, Following, Admin
personalized-activity-for-buddypress-frfwa
Makes Buddypress Activity Personalized For Users, by Including Activity Feeds Only From Users They Are Friends With, Users They Are Following And Administrator of Your Community.
BuddyPress Extended Friendship Request Developer Profile
12 plugins · 2K total installs
How We Detect BuddyPress Extended Friendship Request
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buddypress-extended-friendship-request/assets/js/bp-extended-friendship-request-nouveau.js/wp-content/plugins/buddypress-extended-friendship-request/assets/js/bp-extended-friendship-request.js/wp-content/plugins/buddypress-extended-friendship-request/assets/vendors/webui/jquery.webui-popover.js/wp-content/plugins/buddypress-extended-friendship-request/assets/vendors/webui/jquery.webui-popover.css/wp-content/plugins/buddypress-extended-friendship-request/assets/css/bp-extended-friendship-request.cssassets/js/bp-extended-friendship-request-nouveau.jsassets/js/bp-extended-friendship-request.jsassets/vendors/webui/jquery.webui-popover.jsbuddypress-extended-friendship-request/assets/js/bp-extended-friendship-request-nouveau.js?ver=buddypress-extended-friendship-request/assets/js/bp-extended-friendship-request.js?ver=buddypress-extended-friendship-request/assets/vendors/webui/jquery.webui-popover.js?ver=buddypress-extended-friendship-request/assets/vendors/webui/jquery.webui-popover.css?ver=HTML / DOM Fingerprints
bp-ext-friendship-message<!-- Start: BuddyPress Extended Friendship Request Form Template --><!-- End: BuddyPress Extended Friendship Request Form Template -->data-plugin-pathBPExtendedFriendshipRequest