
Plugin Name: Buddypress profile view from admin Security & Risk Analysis
wordpress.org/plugins/buddypress-profile-view-from-adminThis plugin allows admin user to view buddypress profile from admin amd will not work without buddypress.
Is Plugin Name: Buddypress profile view from admin Safe to Use in 2026?
Generally Safe
Score 85/100Plugin Name: Buddypress profile view from admin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "buddypress-profile-view-from-admin" v1.0 plugin exhibits a mixed security posture. On the positive side, the plugin boasts a minimal attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are reported as using prepared statements, and there are no known CVEs associated with this plugin, suggesting a history of relatively secure development or limited exposure. The absence of file operations and external HTTP requests also reduces potential attack vectors.
However, a significant concern arises from the static analysis results indicating that 0% of outputs are properly escaped. This presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or data processed by the plugin could be injected into the page without proper sanitization. The single taint flow with unsanitized paths, even if not classified as critical or high severity, warrants attention, especially in conjunction with the unescaped outputs. The complete lack of nonce checks and capability checks across all entry points, though the entry points are currently zero, signifies a lack of defensive coding practices that could become a vulnerability if new entry points are introduced in future updates without addressing these fundamental security controls.
In conclusion, while the plugin benefits from a small attack surface and a clean vulnerability history, the unescaped outputs are a critical weakness that could lead to serious security issues. The absence of essential security checks like nonces and capability checks, even with zero current entry points, is a potential future risk. Developers should prioritize addressing the output escaping before considering any feature enhancements.
Key Concerns
- Unescaped output (7 total outputs)
- Taint flow with unsanitized paths (1 total)
- No nonce checks
- No capability checks
Plugin Name: Buddypress profile view from admin Security Vulnerabilities
Plugin Name: Buddypress profile view from admin Code Analysis
Output Escaping
Data Flow Analysis
Plugin Name: Buddypress profile view from admin Attack Surface
WordPress Hooks 3
Maintenance & Trust
Plugin Name: Buddypress profile view from admin Maintenance & Trust
Maintenance Signals
Community Trust
Plugin Name: Buddypress profile view from admin Alternatives
Registration Options for BuddyPress
bp-registration-options
Moderate new BuddyPress members and fight BuddyPress spam.
BuddyPress Automatic Friends
bp-automatic-friends
Automatically create and accept friendships for specified users upon new user registration. * Requires BuddyPress
BuddyPress Admin Only Profile Fields
buddypress-admin-only-profile-fields
Easily set the visibility of BuddyPress profile fields to hidden, allowing only admin users to edit and view them.
BP Devolved Authority
bp-devolved-authority
This plugin allows key aspects of BuddyPress administration to be devolved to non admin users.
Add All Nav Links to BP Adminbar
add-all-nav-links-to-bp-adminbar
Automatically include dropdowns of all Buddypress component and Wordpress menus in the BP Adminbar.
Plugin Name: Buddypress profile view from admin Developer Profile
2 plugins · 20 total installs
How We Detect Plugin Name: Buddypress profile view from admin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buddypress-profile-view-from-admin/css/style.cssbuddypress_profile_admin_css