BuddyPress Forums – Move Topic (Planned: Split and Merge Topic) Security & Risk Analysis

wordpress.org/plugins/buddypress-forums-move-topic-planned-split-and-merge-topic

Provides a drop-down on Forum Topic page so Group Admins / Moderators can move topic thread to another forum. Generates email alert to topic author.

10 active installs v0.0.6 PHP + WP 2.9.2+ Updated Apr 20, 2010
buddypressforumsgroup-forumsmove-topic
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BuddyPress Forums – Move Topic (Planned: Split and Merge Topic) Safe to Use in 2026?

Generally Safe

Score 85/100

BuddyPress Forums – Move Topic (Planned: Split and Merge Topic) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The plugin "buddypress-forums-move-topic-planned-split-and-merge-topic" v0.0.6 presents a mixed security posture. On the positive side, all SQL queries utilize prepared statements, and there are no known CVEs or external HTTP requests, suggesting some attention to common vulnerabilities. However, significant concerns arise from the static analysis. The complete absence of output escaping across all identified output points is a critical flaw, leaving the plugin highly susceptible to Cross-Site Scripting (XSS) attacks.

Furthermore, the taint analysis reveals two high-severity flows with unsanitized paths. While the exact nature of these flows isn't detailed, unsanitized paths in conjunction with potentially dangerous function usage (even if currently zero) and the lack of capability checks or nonce verification on potential entry points (which are noted as zero, but this could be an oversight in analysis or indicative of a very limited feature set) present a substantial risk. The vulnerability history, while currently clean, cannot mitigate the risks identified in the static analysis, especially the lack of output escaping.

In conclusion, while the plugin avoids some common pitfalls like raw SQL and known exploits, the critical lack of output escaping and the high-severity taint flows are major security weaknesses that require immediate attention. The plugin's current feature set seems limited, which might explain the zero entry points, but the identified coding practices are concerning. A thorough review and remediation of the output escaping and taint flow issues are essential.

Key Concerns

  • No output escaping on any output points
  • High severity taint flows with unsanitized paths (x2)
  • No capability checks
  • No nonce checks
Vulnerabilities
None known

BuddyPress Forums – Move Topic (Planned: Split and Merge Topic) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

BuddyPress Forums – Move Topic (Planned: Split and Merge Topic) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
16 prepared
Unescaped Output
10
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
14
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared16 total queries

Output Escaping

0% escaped10 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
bp_fmt_setup_forum_list_COPY (buddypress-forums-move-topic.php:120)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

BuddyPress Forums – Move Topic (Planned: Split and Merge Topic) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionbp_before_group_forum_contentbuddypress-forums-move-topic.php:195
actiongroups_new_group_forumbuddypress-forums-move-topic.php:197
actionbp_initloader.php:15
Maintenance & Trust

BuddyPress Forums – Move Topic (Planned: Split and Merge Topic) Maintenance & Trust

Maintenance Signals

WordPress version tested2.9.2
Last updatedApr 20, 2010
PHP min version
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

BuddyPress Forums – Move Topic (Planned: Split and Merge Topic) Developer Profile

3sixty

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BuddyPress Forums – Move Topic (Planned: Split and Merge Topic)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about BuddyPress Forums – Move Topic (Planned: Split and Merge Topic)