
BuddyPress No Mentions Security & Risk Analysis
wordpress.org/plugins/buddypress-no-mentionsDisable the @mentions capability in BuddyPress. Perfect for users who don't understand Twitter!
Is BuddyPress No Mentions Safe to Use in 2026?
Generally Safe
Score 85/100BuddyPress No Mentions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis and vulnerability history, the "buddypress-no-mentions" v1.0.1 plugin exhibits a strong security posture. The absence of any identified dangerous functions, SQL queries without prepared statements, unescaped output, file operations, or external HTTP requests suggests robust coding practices. Furthermore, the lack of any vulnerability history, including critical or high severity CVEs, indicates a history of stable and secure development. The complete absence of any identified attack surface points, such as unprotected AJAX handlers, REST API routes, or shortcodes, further solidifies its secure design. The zero taint flows with unsanitized paths, especially critical or high severity ones, are particularly encouraging.
While the plugin's current state appears very secure, the absence of nonces and capability checks is a minor concern that could potentially become a weakness if the plugin were to evolve to include more complex functionality or user-interactive features in the future. However, given the current feature set indicated by the analysis (likely solely focused on disabling mentions), this absence is unlikely to pose an immediate risk. Overall, this plugin demonstrates excellent security hygiene, with no evident vulnerabilities or significant risks based on the provided data.
Key Concerns
- No nonce checks found
- No capability checks found
BuddyPress No Mentions Security Vulnerabilities
BuddyPress No Mentions Code Analysis
BuddyPress No Mentions Attack Surface
WordPress Hooks 5
Maintenance & Trust
BuddyPress No Mentions Maintenance & Trust
Maintenance Signals
Community Trust
BuddyPress No Mentions Alternatives
BuddyPress Messaging Control
bp-messaging-control
This plugin is a Swiss Army Knife for messaging, It allows the site admin to place restrictions on public and private messages including general rules …
Mentions légales [FR]
hjqs-mentions-legales-fr
Le plugin vous permet de générer automatiquement vos mentions légales, votre politique de confidentialité et vos conditions générales de vente en quel …
Display Tweets
display-tweets-php
Display Tweets is an easy to use, future proof Twitter feed plugin that uses PHP to make requests to the v1.1 Twitter REST API.
Mentions Legales Par Webdeclic
mentions-legales-par-webdeclic
Génère un shortcode pour les mentions légales qui sont obligatoires sur les sites internet en France.
Twitter Mentions As Comments
twitter-mentions-as-comments
Twitter Mentions as Comments scours Twitter for people talking about your site & silently inserts their Tweets alongside your existing comments.
BuddyPress No Mentions Developer Profile
8 plugins · 380 total installs
How We Detect BuddyPress No Mentions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
notification-settingszebrahighlightname="notifications[notification_activity_new_reply]"bp