
BuddyPress Extended Profile Translation Security & Risk Analysis
wordpress.org/plugins/buddypress-extended-profile-translationMultilingual Extended Profiles in multisite BuddyPress
Is BuddyPress Extended Profile Translation Safe to Use in 2026?
Generally Safe
Score 85/100BuddyPress Extended Profile Translation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "buddypress-extended-profile-translation" v1.0 reveals a generally strong security posture with no critical or high-severity vulnerabilities identified in code signals or taint analysis. The plugin demonstrates good practices by including a nonce check and a capability check, indicating an awareness of basic security measures. Furthermore, the absence of file operations and external HTTP requests reduces the attack surface. The plugin's vulnerability history is also clean, with no recorded CVEs, suggesting a consistent track record of security. However, a significant concern is the presence of two SQL queries that do not use prepared statements. While the total number of queries is small, this practice, especially without any exploitable taint flows found, still introduces a potential risk of SQL injection if the data used in these queries were to be influenced by user input in a way not yet detected or if future code changes introduce such a pathway. The low percentage of properly escaped output also indicates a potential for cross-site scripting (XSS) vulnerabilities, although no specific flows were identified in this analysis. Overall, the plugin is relatively secure, but the raw SQL queries and output escaping practices warrant attention to further harden its security.
Key Concerns
- SQL queries not using prepared statements
- Low percentage of properly escaped output
BuddyPress Extended Profile Translation Security Vulnerabilities
BuddyPress Extended Profile Translation Code Analysis
SQL Query Safety
Output Escaping
BuddyPress Extended Profile Translation Attack Surface
WordPress Hooks 3
Maintenance & Trust
BuddyPress Extended Profile Translation Maintenance & Trust
Maintenance Signals
Community Trust
BuddyPress Extended Profile Translation Alternatives
Zanto WP Translation (For Multisites)
zanto
Zanto WP Translation helps you run a multilingual site by providing linkage between content in blogs of different languages in a WordPress multisite.
WPMMCC
wpmmcc
Multilingual solution for WordPress with automatic translation and site group management.
Polylang
polylang
Go multilingual in a simple and efficient way. Keep writing posts and taxonomy terms as usual while defining their languages all at once.
WP Multilang – Translation and Multilingual Plugin
wp-multilang
Multilingual plugin for WordPress. Go Multilingual in minutes with full WordPress support. Translate your site easily with this localization plugin.
Multisite Language Switcher
multisite-language-switcher
A simple, powerful and easy-to-use plugin that will help you to manage multilingual content in a multisite WordPress installation.
BuddyPress Extended Profile Translation Developer Profile
5 plugins · 140 total installs
How We Detect BuddyPress Extended Profile Translation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buddypress-extended-profile-translation/admin-xprofile.cssHTML / DOM Fingerprints
groupfieldchildsuccessfailure