BuddyPress No Mentions Security & Risk Analysis

wordpress.org/plugins/buddypress-no-mentions

Disable the @mentions capability in BuddyPress. Perfect for users who don't understand Twitter!

10 active installs v1.0.1 PHP + WP + Updated Nov 18, 2010
buddypressmentionmentions
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BuddyPress No Mentions Safe to Use in 2026?

Generally Safe

Score 85/100

BuddyPress No Mentions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

Based on the static analysis and vulnerability history, the "buddypress-no-mentions" v1.0.1 plugin exhibits a strong security posture. The absence of any identified dangerous functions, SQL queries without prepared statements, unescaped output, file operations, or external HTTP requests suggests robust coding practices. Furthermore, the lack of any vulnerability history, including critical or high severity CVEs, indicates a history of stable and secure development. The complete absence of any identified attack surface points, such as unprotected AJAX handlers, REST API routes, or shortcodes, further solidifies its secure design. The zero taint flows with unsanitized paths, especially critical or high severity ones, are particularly encouraging.

While the plugin's current state appears very secure, the absence of nonces and capability checks is a minor concern that could potentially become a weakness if the plugin were to evolve to include more complex functionality or user-interactive features in the future. However, given the current feature set indicated by the analysis (likely solely focused on disabling mentions), this absence is unlikely to pose an immediate risk. Overall, this plugin demonstrates excellent security hygiene, with no evident vulnerabilities or significant risks based on the provided data.

Key Concerns

  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

BuddyPress No Mentions Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

BuddyPress No Mentions Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

BuddyPress No Mentions Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedbp-no-mentions.php:6
actionbp_notification_settingsbp-no-mentions.php:18
actioninitbp-no-mentions.php:21
actionwp_headbp-no-mentions.php:25
actionbp_initloader.php:14
Maintenance & Trust

BuddyPress No Mentions Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedNov 18, 2010
PHP min version
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

BuddyPress No Mentions Developer Profile

r-a-y

8 plugins · 380 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BuddyPress No Mentions

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
notification-settingszebrahighlight
Data Attributes
name="notifications[notification_activity_new_reply]"
JS Globals
bp
FAQ

Frequently Asked Questions about BuddyPress No Mentions