
BP Login Redirect Security & Risk Analysis
wordpress.org/plugins/buddypress-login-redirectAllows to decide buddypress website admins where their users should land after log in.
Is BP Login Redirect Safe to Use in 2026?
Generally Safe
Score 85/100BP Login Redirect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "buddypress-login-redirect" plugin v2.2 exhibits a strong security posture from a static analysis perspective, with no identified dangerous functions, SQL queries not using prepared statements, file operations, external HTTP requests, or bundled libraries. The complete absence of an attack surface with unprotected entry points is also a significant positive. However, a major concern arises from the 100% of output functions not being properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where untrusted input could be injected into the output, potentially leading to malicious code execution in a user's browser. The plugin's vulnerability history is clean, with no known CVEs, which is excellent. Despite the lack of direct code execution or data manipulation risks identified in the static analysis, the unescaped output is a critical weakness that needs immediate attention. The plugin has good practices in preventing direct code execution vulnerabilities but falls short in output sanitization.
Key Concerns
- Output not properly escaped
BP Login Redirect Security Vulnerabilities
BP Login Redirect Code Analysis
Output Escaping
BP Login Redirect Attack Surface
WordPress Hooks 4
Maintenance & Trust
BP Login Redirect Maintenance & Trust
Maintenance Signals
Community Trust
BP Login Redirect Alternatives
BP Profile as Homepage Fork
bp-profile-as-homepage-fork
This plugin lets you have a normal site Homepage for visitors while logged-in users have their BP Profile as Homepage. This is similar to Facebook.
JSON API User
json-api-user
Extends the JSON API Plugin to allow RESTful user registration, authentication & many other User Meta, BP functions. A Pro version is also available.
BuddyPress Login Redirect to Profile
bp-redirect-to-profile
Redirect users to their BuddyPress profile on login.
Inactive Logout
inactive-logout
Automatically logout idle user sessions, with logout redirections and concurrent limit logins all in one place.
Login Logout Menu
login-logout-menu
Login Logout Menu is a handy plugin which allows you to add login, logout, register and profile menu items in your selected menu.
BP Login Redirect Developer Profile
7 plugins · 540 total installs
How We Detect BP Login Redirect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.