
BuddyPress Forums – Move Topic (Planned: Split and Merge Topic) Security & Risk Analysis
wordpress.org/plugins/buddypress-forums-move-topic-planned-split-and-merge-topicProvides a drop-down on Forum Topic page so Group Admins / Moderators can move topic thread to another forum. Generates email alert to topic author.
Is BuddyPress Forums – Move Topic (Planned: Split and Merge Topic) Safe to Use in 2026?
Generally Safe
Score 85/100BuddyPress Forums – Move Topic (Planned: Split and Merge Topic) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "buddypress-forums-move-topic-planned-split-and-merge-topic" v0.0.6 presents a mixed security posture. On the positive side, all SQL queries utilize prepared statements, and there are no known CVEs or external HTTP requests, suggesting some attention to common vulnerabilities. However, significant concerns arise from the static analysis. The complete absence of output escaping across all identified output points is a critical flaw, leaving the plugin highly susceptible to Cross-Site Scripting (XSS) attacks.
Furthermore, the taint analysis reveals two high-severity flows with unsanitized paths. While the exact nature of these flows isn't detailed, unsanitized paths in conjunction with potentially dangerous function usage (even if currently zero) and the lack of capability checks or nonce verification on potential entry points (which are noted as zero, but this could be an oversight in analysis or indicative of a very limited feature set) present a substantial risk. The vulnerability history, while currently clean, cannot mitigate the risks identified in the static analysis, especially the lack of output escaping.
In conclusion, while the plugin avoids some common pitfalls like raw SQL and known exploits, the critical lack of output escaping and the high-severity taint flows are major security weaknesses that require immediate attention. The plugin's current feature set seems limited, which might explain the zero entry points, but the identified coding practices are concerning. A thorough review and remediation of the output escaping and taint flow issues are essential.
Key Concerns
- No output escaping on any output points
- High severity taint flows with unsanitized paths (x2)
- No capability checks
- No nonce checks
BuddyPress Forums – Move Topic (Planned: Split and Merge Topic) Security Vulnerabilities
BuddyPress Forums – Move Topic (Planned: Split and Merge Topic) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
BuddyPress Forums – Move Topic (Planned: Split and Merge Topic) Attack Surface
WordPress Hooks 3
Maintenance & Trust
BuddyPress Forums – Move Topic (Planned: Split and Merge Topic) Maintenance & Trust
Maintenance Signals
Community Trust
BuddyPress Forums – Move Topic (Planned: Split and Merge Topic) Alternatives
bbPress Messages
bbp-messages
bbPress Messages - Simple yet powerful private messaging system tailored for bbPress.
BP Multiple Forum Post
bp-multiple-forum-post
Lets users cross-post a new bbpress forum topic in multiple BuddyPress group forums.
bpCKEditor
bpckeditor
This plugin replaces the plain multiline text field on BP forums by a CKEditor.
Group Forum Subscripton for BuddyPress
group-forum-subscription-for-buddypress
** Use of this plugin is not recommended in versions of BuddyPress 1.2 and higher. Please consider using BuddyPress Group Activity Notifications inste …
Forum Redirect
forum-redirect
Allows you to override the default behavior of bbPress forums, linking them to an external site.
BuddyPress Forums – Move Topic (Planned: Split and Merge Topic) Developer Profile
1 plugin · 10 total installs
How We Detect BuddyPress Forums – Move Topic (Planned: Split and Merge Topic)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.