BuddyPress Private Messages for Friends Only Security & Risk Analysis

wordpress.org/plugins/buddypress-private-message-for-friends-only

This plugin only allows friends and site administrators to send private messages on your BuddyPress site.

20 active installs v1.1 PHP + WP + Updated Jun 4, 2010
buddypressmessagepmprivate-messagespam
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BuddyPress Private Messages for Friends Only Safe to Use in 2026?

Generally Safe

Score 85/100

BuddyPress Private Messages for Friends Only has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The static analysis of the 'buddypress-private-message-for-friends-only' plugin v1.1 reveals an exceptionally clean code base. There are no identified attack surfaces, dangerous functions, unescaped outputs, file operations, external HTTP requests, or unsanitized taint flows. The plugin also demonstrates excellent security practices by utilizing prepared statements for all SQL queries and performing nonce and capability checks where applicable. The absence of any recorded vulnerabilities in its history further reinforces this positive security posture.

While the current analysis shows no immediate security concerns, the complete lack of identified entry points and specific checks is notable. It suggests either a very small and well-contained plugin or, potentially, that some security mechanisms might be overlooked in the static analysis process for this specific version. The plugin's reliance on BuddyPress for core functionality means that any vulnerabilities in BuddyPress itself could indirectly impact this plugin, though this is external to the plugin's direct code.

Overall, this plugin exhibits a very strong security profile based on the provided data, with excellent adherence to secure coding practices and no known historical vulnerabilities. The absence of any detected issues is a significant strength, indicating a highly secure implementation. The primary area for caution, if any, would be ensuring that any future updates or integrations maintain this level of security awareness.

Vulnerabilities
None known

BuddyPress Private Messages for Friends Only Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BuddyPress Private Messages for Friends Only Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

BuddyPress Private Messages for Friends Only Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionbp_initbp-pms-for-friends-loader.php:17
actionmessages_message_before_savebp-pms-for-friends.php:15
actioninitbp-pms-for-friends.php:16
actionwp_headbp-pms-for-friends.php:17
actionadmin_noticesbp-pms-for-friends.php:20
Maintenance & Trust

BuddyPress Private Messages for Friends Only Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedJun 4, 2010
PHP min version
Downloads11K

Community Trust

Rating100/100
Number of ratings3
Active installs20
Developer Profile

BuddyPress Private Messages for Friends Only Developer Profile

r-a-y

8 plugins · 380 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BuddyPress Private Messages for Friends Only

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
send-private-message
FAQ

Frequently Asked Questions about BuddyPress Private Messages for Friends Only