
BuddyPress Forums Extras – View Activity Comments on Forum Posts Security & Risk Analysis
wordpress.org/plugins/buddypress-group-forum-extrasThis plugin is a collection of sub-plugins for group forums. Signatures, bbCode lite, ShortCodes, Ajaxed Quote, RSS Feeds, Forum Index (and Widget), A …
Is BuddyPress Forums Extras – View Activity Comments on Forum Posts Safe to Use in 2026?
Generally Safe
Score 85/100BuddyPress Forums Extras – View Activity Comments on Forum Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "buddypress-group-forum-extras" plugin v0.3.0 exhibits several concerning security practices, despite a clean vulnerability history. The most significant issue is the presence of an unprotected AJAX handler, which represents a direct attack vector without any authentication or authorization checks. This, coupled with the use of the `create_function` dangerous function, suggests a potential for code injection or execution vulnerabilities if the AJAX handler's input is not properly sanitized. Furthermore, the complete lack of prepared statements for SQL queries is a major red flag, exposing the plugin to SQL injection vulnerabilities. The extremely low percentage of properly escaped output indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered directly in the browser without sufficient encoding.
While the plugin has no recorded CVEs and no critical or high severity taint flows were identified in the static analysis, this should not be interpreted as a sign of robust security. The absence of vulnerabilities in the past may be due to luck, limited exposure, or the fact that the identified weaknesses have not yet been exploited. The code analysis strongly indicates that the plugin is not following fundamental WordPress security best practices, making it a risky component to use. The combination of an unprotected entry point, raw SQL queries, and insufficient output escaping creates a fertile ground for attackers.
Key Concerns
- Unprotected AJAX handler
- Dangerous function: create_function
- SQL queries without prepared statements
- Low percentage of properly escaped output
- No capability checks on entry points
BuddyPress Forums Extras – View Activity Comments on Forum Posts Security Vulnerabilities
BuddyPress Forums Extras – View Activity Comments on Forum Posts Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
BuddyPress Forums Extras – View Activity Comments on Forum Posts Attack Surface
AJAX Handlers 1
WordPress Hooks 83
Maintenance & Trust
BuddyPress Forums Extras – View Activity Comments on Forum Posts Maintenance & Trust
Maintenance Signals
Community Trust
BuddyPress Forums Extras – View Activity Comments on Forum Posts Alternatives
BP Custom Functionalities
bp-custom-functionalities
BP Custom Functionalities provides custom functionalities that regular BuddyPress users requires.
BP Classic
bp-classic
BP Classic, a BuddyPress (12.0.0 & up) backwards compatibility add-on
GD bbPress Tools
gd-bbpress-tools
Adds different expansions and tools to the bbPress plugin powered forums: BBCode support, signatures, various tweaks, custom views, quote...
Signature Add-On for Gravity Forms
gravity-signature-forms-add-on
Automatically generate a legally binding & court recognized contract from a Gravity Forms submission. Proposals. Time sheets. Contracts.
Signature Add-On for WooCommerce
woocommerce-digital-signature
Automatically require your WooCommerce customers to sign a legally binding contract before downloading your product. Easy to Use.
BuddyPress Forums Extras – View Activity Comments on Forum Posts Developer Profile
10 plugins · 200 total installs
How We Detect BuddyPress Forums Extras – View Activity Comments on Forum Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buddypress-group-forum-extras/_inc/js/bp-forums-extras-activity.jsHTML / DOM Fingerprints
forum-post-activityactivity-stream-post-acomment-avataracomment-metaacomment-contentid="activity-id="activity-stream-post-id="view-activity-comment-id="acomment-<li id="activity-<ul id="activity-stream-post-<div class="activity-comments" id="view-activity-comment-<li id="acomment-