
BuddyPress Friends On-Line Security & Risk Analysis
wordpress.org/plugins/buddypress-friends-on-linePlugin will display on your Friends page a new tab called Online with a list of currently online friends.
Is BuddyPress Friends On-Line Safe to Use in 2026?
Generally Safe
Score 85/100BuddyPress Friends On-Line has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "buddypress-friends-on-line" plugin, version 0.4.3.1, exhibits a generally positive security posture based on the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code does not utilize dangerous functions, engage in file operations, make external HTTP requests, or bundle external libraries, all of which are good security practices. The use of prepared statements for all SQL queries is also a strong indicator of secure database interaction.
However, a notable concern arises from the output escaping. With 50% of outputs not being properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. If user-supplied data is being outputted directly to the browser without adequate sanitization or escaping, an attacker could potentially inject malicious scripts. The lack of any capability checks or nonce checks, coupled with zero identified taint flows, suggests that while direct code execution or data manipulation vulnerabilities may be absent, the XSS risk due to unescaped output remains.
The plugin's vulnerability history is clean, with no recorded CVEs. This indicates a lack of previously identified security flaws. However, the absence of findings in the taint analysis, combined with the lack of capability checks, could also suggest that the analysis might not have covered all potential interaction points or that the plugin's functionality is very limited. The most pressing concern is the high percentage of unescaped output, which presents a clear and present danger for XSS vulnerabilities, despite the otherwise clean static analysis and vulnerability history.
Key Concerns
- High percentage of unescaped output (50%)
- Lack of capability checks
- Lack of nonce checks
BuddyPress Friends On-Line Security Vulnerabilities
BuddyPress Friends On-Line Release Timeline
BuddyPress Friends On-Line Code Analysis
Output Escaping
BuddyPress Friends On-Line Attack Surface
WordPress Hooks 3
Maintenance & Trust
BuddyPress Friends On-Line Maintenance & Trust
Maintenance Signals
Community Trust
BuddyPress Friends On-Line Alternatives
Invite Anyone
invite-anyone
Makes BuddyPress's invitation features more powerful.
CBX User Online & Last Login
cbxuseronline
Shows online users based on cookie for guest and session for registered user. It also records the last login of user.
BuddyPress Extended Friendship Request
buddypress-extended-friendship-request
BuddyPress Extended Friendship Request plugin allows users to send a personalized message with the friendship requests.
BuddyPress Automatic Friends
bp-automatic-friends
Automatically create and accept friendships for specified users upon new user registration. * Requires BuddyPress
Mutual Buddies
mutual-buddies
Mutual buddies displays BuddyPress mutual friends of the logged in user & the user whose profile the user is looking at on the Profile page.
BuddyPress Friends On-Line Developer Profile
10 plugins · 3K total installs
How We Detect BuddyPress Friends On-Line
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buddypress-friends-on-line/css/bp-friends-on-line.css/wp-content/plugins/buddypress-friends-on-line/js/bp-friends-on-line.js/wp-content/plugins/buddypress-friends-on-line/js/bp-friends-on-line.jsbuddypress-friends-on-line/css/bp-friends-on-line.css?ver=buddypress-friends-on-line/js/bp-friends-on-line.js?ver=HTML / DOM Fingerprints
friends-onlinebpfol-custom-widgetitem-avataritem-titleitem-metaactivityavatar-blockid="members-list"class="item-list"