BuddyPress Last Active Users (wp-admin) Security & Risk Analysis

wordpress.org/plugins/buddypress-last-active-users-wp-admin

Display BuddyPress last active date for a user on wp-admin/users.php page

10 active installs v1.1 PHP + WP + Updated Jan 5, 2015
buddypressdatemembersuserswp-admin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BuddyPress Last Active Users (wp-admin) Safe to Use in 2026?

Generally Safe

Score 85/100

BuddyPress Last Active Users (wp-admin) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The WordPress plugin "buddypress-last-active-users-wp-admin" version 1.1 exhibits an exceptionally strong security posture based on the provided static analysis. There are no identified entry points, dangerous functions, SQL queries without prepared statements, unescaped outputs, file operations, or external HTTP requests. Furthermore, the absence of any vulnerability history, including CVEs, common vulnerability types, or past issues, suggests a well-maintained and secure codebase. The plugin demonstrates excellent adherence to secure coding practices by implementing robust checks and safeguards across all analyzed components.

However, the analysis also highlights an extremely limited attack surface. With zero AJAX handlers, REST API routes, shortcodes, or cron events, the plugin offers no direct interaction points for potential attackers. While this significantly reduces the risk of exploitation, it also means that the plugin's functionality, if any, is not exposed through standard WordPress extension mechanisms. This lack of exposed functionality could be a strength in terms of security but may also indicate a very niche or perhaps incomplete plugin. Overall, the plugin appears to be very secure with no immediate exploitable vulnerabilities indicated by the data. The plugin's strengths lie in its clean code and complete lack of historical vulnerabilities, while its weakness, if it can be called that, is its extremely small attack surface, which makes it difficult to assess the security of its core features.

Vulnerabilities
None known

BuddyPress Last Active Users (wp-admin) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

BuddyPress Last Active Users (wp-admin) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

BuddyPress Last Active Users (wp-admin) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filtermanage_users_columnsbpla-users.php:15
filterwpmu_users_columnsbpla-users.php:16
actionmanage_users_custom_columnbpla-users.php:17
actionbp_initbpla-users.php:20
Maintenance & Trust

BuddyPress Last Active Users (wp-admin) Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedJan 5, 2015
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

BuddyPress Last Active Users (wp-admin) Developer Profile

Slava Abakumov

8 plugins · 3K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
104 days
View full developer profile
Detection Fingerprints

How We Detect BuddyPress Last Active Users (wp-admin)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/buddypress-last-active-users-wp-admin/bpla-users.php

HTML / DOM Fingerprints

CSS Classes
column-bp_last_active
FAQ

Frequently Asked Questions about BuddyPress Last Active Users (wp-admin)