
BuddyPress Group Wiki Security & Risk Analysis
wordpress.org/plugins/buddypress-group-wikiThis plugin provides simple group wiki functionality within BuddyPress. REQUIRES WPMU!
Is BuddyPress Group Wiki Safe to Use in 2026?
Generally Safe
Score 85/100BuddyPress Group Wiki has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "buddypress-group-wiki" v1.8 plugin exhibits a mixed security posture. On the positive side, it demonstrates a strong adherence to secure coding practices by predominantly using prepared statements for SQL queries and having no recorded vulnerabilities or CVEs. The absence of critical or high-severity taint flows is also a significant strength, indicating that data is generally handled with care. However, there are notable concerns. The presence of the `shell_exec` function, a powerful tool that can be misused for remote code execution if user input is not meticulously sanitized, is a significant red flag. Furthermore, the single unprotected AJAX handler presents a direct entry point for unauthenticated attackers. The low percentage of properly escaped output further exacerbates this risk, as it increases the likelihood of cross-site scripting (XSS) vulnerabilities through the unprotected AJAX endpoint or other potential input vectors.
Key Concerns
- Unprotected AJAX handler
- Use of dangerous function: shell_exec
- Low output escaping percentage
BuddyPress Group Wiki Security Vulnerabilities
BuddyPress Group Wiki Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
BuddyPress Group Wiki Attack Surface
AJAX Handlers 1
WordPress Hooks 15
Maintenance & Trust
BuddyPress Group Wiki Maintenance & Trust
Maintenance Signals
Community Trust
BuddyPress Group Wiki Alternatives
BuddyPress Group Email Subscription
buddypress-group-email-subscription
This powerful plugin allows users to receive email notifications of group activity. Weekly or daily digests are available.
BuddyPress Docs
buddypress-docs
Adds collaborative Docs to BuddyPress.
Registration Options for BuddyPress
bp-registration-options
Moderate new BuddyPress members and fight BuddyPress spam.
Wbcom Designs – Shortcodes & Elementor Widgets For BuddyPress
shortcodes-for-buddypress
This plugin generates shortcodes for Listing Activity Streams, Members, and Groups on any website post or page.
BuddyPress Default Data
bp-default-data
Plugin will create lots of users, messages, friends connections, groups, topics, activity items, profile data - useful for testing purpose.
BuddyPress Group Wiki Developer Profile
5 plugins · 50 total installs
How We Detect BuddyPress Group Wiki
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buddypress-group-wiki/css/style.css/wp-content/plugins/buddypress-group-wiki/js/script.js/wp-content/plugins/buddypress-group-wiki/js/tiny_mce/tiny_mce.jswp-content/plugins/buddypress-group-wiki/js/script.jswp-content/plugins/buddypress-group-wiki/js/tiny_mce/tiny_mce.jsbuddypress-group-wiki/css/style.css?ver=buddypress-group-wiki/js/script.js?ver=buddypress-group-wiki/js/tiny_mce/tiny_mce.js?ver=HTML / DOM Fingerprints
wiki-page-listwiki-page-contentbp-group-wiki<!-- Wiki Controls --><!-- Wiki Page Content --><!-- Edit Wiki Page -->data-wiki-page-iddata-wiki-group-idtinyMCE