[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQgOx2kSpee3e8fkYR_TX-8L4wcxy56BY24N21cFikgA":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":23,"download_link":24,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28,"vulnerabilities":29,"developer":30,"crawl_stats":27,"alternatives":38,"analysis":132,"fingerprints":206},"buddypress-profile-view-from-admin","Plugin Name: Buddypress profile view from admin","1.0","rameshwor.maharjan","https:\u002F\u002Fprofiles.wordpress.org\u002Frameshwormaharjan\u002F","\u003Cp>This buddypress plugin allows admin  user to view a member profile page from admin user list page.\u003C\u002Fp>\n","This plugin allows admin user to view buddypress profile from admin amd will not work without buddypress.",10,2966,100,1,"2013-09-12T04:44:00.000Z","3.6.1","2.9.1","",[20,21,22],"admin","buddypress","user-profile-view","http:\u002F\u002Fwebavenue.com.au","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbuddypress-profile-view-from-admin.zip",85,0,null,"2026-03-15T15:16:48.613Z",[],{"slug":31,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":33,"avg_security_score":34,"avg_patch_time_days":35,"trust_score":36,"computed_at":37},"rameshwormaharjan",2,20,93,30,89,"2026-04-04T11:12:00.023Z",[39,60,81,98,116],{"slug":40,"name":41,"version":42,"author":43,"author_profile":44,"description":45,"short_description":46,"active_installs":47,"downloaded":48,"rating":49,"num_ratings":50,"last_updated":51,"tested_up_to":52,"requires_at_least":53,"requires_php":54,"tags":55,"homepage":18,"download_link":59,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"bp-registration-options","Registration Options for BuddyPress","4.4.5","Brian Messenlehner","https:\u002F\u002Fprofiles.wordpress.org\u002Fmessenlehner\u002F","\u003Cp>Prevent users and bots from accessing the BuddyPress or bbPress areas of your website(s) until they are approved.\u003C\u002Fp>\n\u003Cp>This BuddyPress extension allows you to enable user moderation for new members, as well as help create a private network for your users. If moderation is enabled, any new members will be denied access to your BuddyPress and bbPress areas on your site, with the exception of their own user profile. They will be allowed to edit and configure that much. They will also not be listed in the members lists on the frontend until approved. Custom messages are available so you can tailor them to the tone of your website and community. When an admin approves or denies a user, email notifications will be sent to let them know of the decision.\u003C\u002Fp>\n\u003Cp>Requires BuddyPress version 1.7 or higher and bbPress 2.0 or higher.\u003C\u002Fp>\n\u003Ch3>General Data Protection Regulation\u003C\u002Fh3>\n\u003Cp>BuddyPress Registration Options temporarily stores user IP addresses as user meta to help validate and vet pending users. Saved IP values are deleted upon both approval and denial of pending user. No other personal data is recorded.\u003C\u002Fp>\n","Moderate new BuddyPress members and fight BuddyPress spam.",1000,175480,88,33,"2023-03-05T15:26:00.000Z","6.0.11","5.2","5.6",[20,21,56,57,58],"groups","moderation","registration","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbp-registration-options.zip",{"slug":61,"name":62,"version":63,"author":64,"author_profile":65,"description":66,"short_description":67,"active_installs":68,"downloaded":69,"rating":70,"num_ratings":71,"last_updated":72,"tested_up_to":73,"requires_at_least":74,"requires_php":18,"tags":75,"homepage":79,"download_link":80,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"bp-automatic-friends","BuddyPress Automatic Friends","2.0.8","Steven Word","https:\u002F\u002Fprofiles.wordpress.org\u002Fstevenkword\u002F","\u003Cp>Automatically create and accept friendships for specified users upon new user registration. * Requires BuddyPress\u003C\u002Fp>\n","Automatically create and accept friendships for specified users upon new user registration. * Requires BuddyPress",200,26771,84,5,"2022-01-23T16:32:00.000Z","5.9.13","3.5",[20,76,21,77,78],"automatic","friends","instant-friends","http:\u002F\u002Fwww.stevenword.com\u002Fbp-automatic-friends\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbp-automatic-friends.2.0.8.zip",{"slug":82,"name":83,"version":84,"author":85,"author_profile":86,"description":87,"short_description":88,"active_installs":68,"downloaded":89,"rating":13,"num_ratings":32,"last_updated":90,"tested_up_to":91,"requires_at_least":92,"requires_php":18,"tags":93,"homepage":18,"download_link":97,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"buddypress-admin-only-profile-fields","BuddyPress Admin Only Profile Fields","1.2","A5hleyRich","https:\u002F\u002Fprofiles.wordpress.org\u002Fa5hleyrich\u002F","\u003Cp>Easily set the visibility of BuddyPress profile fields to hidden, allowing only admin users to edit and view them.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>GitHub\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>If you would like to contribute to the plugin, you can do so on \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FA5hleyRich\u002FBuddyPress-Admin-Only-Profile-Fields\" rel=\"nofollow ugc\">GitHub\u003C\u002Fa>.\u003C\u002Fp>\n","Easily set the visibility of BuddyPress profile fields to hidden, allowing only admin users to edit and view them.",7208,"2015-11-03T21:00:00.000Z","4.3.34","4.3.1",[20,21,94,95,96],"field","hidden","profile","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbuddypress-admin-only-profile-fields.1.2.zip",{"slug":99,"name":100,"version":101,"author":102,"author_profile":103,"description":104,"short_description":105,"active_installs":33,"downloaded":106,"rating":26,"num_ratings":26,"last_updated":107,"tested_up_to":108,"requires_at_least":18,"requires_php":18,"tags":109,"homepage":113,"download_link":114,"security_score":115,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"bp-devolved-authority","BP Devolved Authority","1.2.0","Venutius","https:\u002F\u002Fprofiles.wordpress.org\u002Fvenutius\u002F","\u003Cp>BP Devolved Authority allows site administrators to devolve the ability to manage Groups, Activity, Members and Emails to other site members. For Xprofile information, you can also give specific individuals the ability to edit the xprofile fields for one or more named individuals.\u003C\u002Fp>\n\u003Cp>BuddyPress has not traditionally allowed site administrators to grant authority to manage aspect of BuddyPress to users without ‘manage_options’ capability. This plugin changes that and allows each of the BP Components to be managed by site members so long as they have the ‘edit_posts’ capability.\u003C\u002Fp>\n\u003Cp>Note that roles allowed to manage members should also have the ‘list_users’ capability, this allows the users list menu item to be displayed in the dashboard for that member.\u003C\u002Fp>\n\u003Cp>The  new feature – individual xprofile management delegation, creates a simple, secure delegation system whereby a privileged user (such as an administrator) can assign other registered BuddyPress members to be “delegates” for a given user. A delegate has the capability to view and edit Extended Profile (XProfile) fields for the delegated user. This is useful on sites where certain relationships exist between one user and another, such as legal guardianship by an adult over a child. Using delegation reduces the need to share passwords or log in to shared accounts.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Roles and capabilities for the delegated xprofile feature\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>This plugin uses the built-in capabilities system as part of WordPress core, along with core BuddyPress hooks (\u003Ccode>bp_current_user_can\u003C\u002Fcode>) to check for appropriate permissions, making it both simple to customize and as secure as WP and BP core code. The custom capabilities are:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>edit_user_delegates\u003C\u002Fcode> – Users with this capability can assign delegates for users they can edit (determined by \u003Ccode>edit_users\u003C\u002Fcode>).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Additionally, the following core capabilities are required:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>list_users\u003C\u002Fcode> – The delegation options implicitly enumerate all registered users, so a user must also have the \u003Ccode>list_users\u003C\u002Fcode> capability to be granted access to the Delegation user interface.\u003C\u002Fli>\n\u003Cli>\u003Ccode>edit_users\u003C\u002Fcode> – If you cannot \u003Ccode>edit_users\u003C\u002Fcode>, you cannot \u003Ccode>edit_user_delegates\u003C\u002Fcode>, either.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>When this option is enabled, the admin can go to the users extended profile tab from the Dashboard>>Users list and choose to delegate authority over the xprofile data to another site member. That site member will then find in their Dashboard>>Users menu and option to see a list of “Devolved Profiles”.\u003C\u002Fp>\n\u003Cp>Once the plugin is activated, visit the Settings>>BP Devolved Authority page to choose which roles can manage your BP Components.\u003C\u002Fp>\n\u003Cp>This plugin needs BuddyPress to work.\u003C\u002Fp>\n","This plugin allows key aspects of BuddyPress administration to be devolved to non admin users.",2937,"2024-07-29T05:05:00.000Z","6.6.5",[110,111,21,112,56],"administrator","bp_moderate","devolved-authority","https:\u002F\u002Fbuddyuser.com\u002Fplugin-bp-devolved-authority","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbp-devolved-authority.1.2.0.zip",92,{"slug":117,"name":118,"version":119,"author":120,"author_profile":121,"description":122,"short_description":123,"active_installs":11,"downloaded":124,"rating":26,"num_ratings":26,"last_updated":125,"tested_up_to":18,"requires_at_least":18,"requires_php":18,"tags":126,"homepage":130,"download_link":131,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"add-all-nav-links-to-bp-adminbar","Add All Nav Links to BP Adminbar","2.1.2","pcwriter","https:\u002F\u002Fprofiles.wordpress.org\u002Fpcwriter\u002F","\u003Cp>Do you, or your users, find having 2 navigation elements a bit confusing? This plugin can aggregate all Buddypress components and WordPress pages\u002Fmenus into the BP Adminbar.\u003C\u002Fp>\n\u003Cp>It provides several user configuration options so you can customize your new admin\u002Fnavbar to your heart’s content. As of this version, you can also use this plugin just to theme your existing bp-adminbar without adding anything to it. See the FAQ for more.\u003C\u002Fp>\n\u003Cp>When the “Add WordPress pages” or “Add Buddypress components” features are enabled, all BP component directory pages (Members, Groups, Forums, etc.) are collected in a Community dropdown, including any from added plugins like BP-Links or BP-Gallery. All WP pages appear in dropdowns that respect whatever page order you have set in your WP backend. Under WP3, they will reflect the page order you set when creating your custom menus. Child and grandchild pages appear in flyout subnavs.\u003C\u002Fp>\n\u003Cp>The plugin code uses standard BP slugs, so if you’ve changed those (through bp-custom or wp-config or whatever other method), they should show as you’ve labeled them.\u003C\u002Fp>\n\u003Cp>All CSS (position, colors, sizes, etc.) can be controlled through your WordPress dashboard under “Settings” > “BP-WP-Navbar” once installed. Make your life easier (and mine too) by using Firefox with the Firebug addon for this!\u003C\u002Fp>\n\u003Cp>If you find this plugin useful or just fun to play with, please show your appreciation by making a small donation to help support addiction recovery at http:\u002F\u002Fnowrecovery.com (donate button in the sidebar). You can view a live demo there too.\u003C\u002Fp>\n","Automatically include dropdowns of all Buddypress component and Wordpress menus in the BP Adminbar.",9108,"2010-11-22T23:24:00.000Z",[127,21,128,129],"adminbar","menu","navbar","http:\u002F\u002Fwordpress.org\u002Fextend\u002Fplugins\u002Fadd-all-nav-links-to-bp-adminbar\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fadd-all-nav-links-to-bp-adminbar.zip",{"attackSurface":133,"codeSignals":153,"taintFlows":176,"riskAssessment":194,"analyzedAt":205},{"hooks":134,"ajaxHandlers":149,"restRoutes":150,"shortcodes":151,"cronEvents":152,"entryPointCount":26,"unprotectedCount":26},[135,140,145],{"type":136,"name":137,"callback":137,"file":138,"line":139},"action","init","buddy-profile-admin.php",44,{"type":141,"name":142,"callback":143,"priority":11,"file":138,"line":144},"filter","user_row_actions","user_action_links",47,{"type":136,"name":146,"callback":147,"file":138,"line":148},"admin_menu","buddypress_profile_admin_menu",48,[],[],[],[],{"dangerousFunctions":154,"sqlUsage":155,"outputEscaping":157,"fileOperations":26,"externalRequests":26,"nonceChecks":26,"capabilityChecks":26,"bundledLibraries":175},[],{"prepared":26,"raw":26,"locations":156},[],{"escaped":26,"rawEcho":158,"locations":159},7,[160,164,166,168,169,171,173],{"file":161,"line":162,"context":163},"view.php",8,"raw output",{"file":161,"line":165,"context":163},9,{"file":161,"line":167,"context":163},13,{"file":161,"line":167,"context":163},{"file":161,"line":170,"context":163},15,{"file":161,"line":172,"context":163},17,{"file":161,"line":174,"context":163},24,[],[177],{"entryPoint":178,"graph":179,"unsanitizedCount":71,"severity":193},"\u003Cview> (view.php:0)",{"nodes":180,"edges":190},[181,185],{"id":182,"type":183,"label":184,"file":161,"line":32},"n0","source","$_REQUEST (x5)",{"id":186,"type":187,"label":188,"file":161,"line":162,"wp_function":189},"n1","sink","echo() [XSS]","echo",[191],{"from":182,"to":186,"sanitized":192},false,"low",{"summary":195,"deductions":196},"The \"buddypress-profile-view-from-admin\" v1.0 plugin exhibits a mixed security posture. On the positive side, the plugin boasts a minimal attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are reported as using prepared statements, and there are no known CVEs associated with this plugin, suggesting a history of relatively secure development or limited exposure. The absence of file operations and external HTTP requests also reduces potential attack vectors.\n\nHowever, a significant concern arises from the static analysis results indicating that 0% of outputs are properly escaped. This presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or data processed by the plugin could be injected into the page without proper sanitization. The single taint flow with unsanitized paths, even if not classified as critical or high severity, warrants attention, especially in conjunction with the unescaped outputs. The complete lack of nonce checks and capability checks across all entry points, though the entry points are currently zero, signifies a lack of defensive coding practices that could become a vulnerability if new entry points are introduced in future updates without addressing these fundamental security controls.\n\nIn conclusion, while the plugin benefits from a small attack surface and a clean vulnerability history, the unescaped outputs are a critical weakness that could lead to serious security issues. The absence of essential security checks like nonces and capability checks, even with zero current entry points, is a potential future risk. Developers should prioritize addressing the output escaping before considering any feature enhancements.",[197,199,201,203],{"reason":198,"points":33},"Unescaped output (7 total outputs)",{"reason":200,"points":162},"Taint flow with unsanitized paths (1 total)",{"reason":202,"points":71},"No nonce checks",{"reason":204,"points":71},"No capability checks","2026-03-17T00:40:24.295Z",{"wat":207,"direct":214},{"assetPaths":208,"generatorPatterns":210,"scriptPaths":211,"versionParams":212},[209],"\u002Fwp-content\u002Fplugins\u002Fbuddypress-profile-view-from-admin\u002Fcss\u002Fstyle.css",[],[],[213],"buddypress_profile_admin_css",{"cssClasses":215,"htmlComments":216,"htmlAttributes":217,"restEndpoints":218,"jsGlobals":219,"shortcodeOutput":220},[],[],[],[],[],[]]