Buddypress Profile Visitors Security & Risk Analysis

wordpress.org/plugins/buddypress-profile-visitors

Show number of profile views count by other members and recent visitors of member profile. And also show who is visiting the perticual member most.

10 active installs v1.9.5 PHP + WP 3.2+ Updated Nov 2, 2020
buddypressprofile-viewsprofile-visitsrecent-profile-visitors
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Buddypress Profile Visitors Safe to Use in 2026?

Generally Safe

Score 85/100

Buddypress Profile Visitors has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of the buddypress-profile-visitors plugin v1.9.5 reveals a generally good security posture with no identified dangerous functions, all SQL queries using prepared statements, and no file operations or external HTTP requests. The absence of taint analysis findings, coupled with zero known CVEs and no recorded vulnerabilities, further suggests a robust security history. However, a significant concern is the complete lack of output escaping, with 0% of outputs being properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could be rendered directly in the browser without sanitization. Additionally, the absence of nonce checks and capability checks across all entry points, although the attack surface is currently reported as zero, presents a potential future risk if new entry points are introduced without proper authorization mechanisms.

Key Concerns

  • 0% output escaping
  • 0 nonce checks on entry points
  • 0 capability checks on entry points
Vulnerabilities
None known

Buddypress Profile Visitors Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Buddypress Profile Visitors Release Timeline

v1.9.5Current
Code Analysis
Analyzed Mar 16, 2026

Buddypress Profile Visitors Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
11 prepared
Unescaped Output
8
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared11 total queries

Output Escaping

0% escaped8 total outputs
Attack Surface

Buddypress Profile Visitors Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionbp_members_screen_display_profilebuddypress_profile_visitors.php:84
actionbp_after_member_headerbuddypress_profile_visitors.php:86
actioninitbuddypress_profile_visitors.php:171
actionbp_after_member_headerincludes\bp_views_core.php:3
Maintenance & Trust

Buddypress Profile Visitors Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedNov 2, 2020
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Buddypress Profile Visitors Developer Profile

chaladi

2 plugins · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Buddypress Profile Visitors

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/buddypress-profile-visitors/includes/style.css

HTML / DOM Fingerprints

CSS Classes
bp_dhrusya_visitors
FAQ

Frequently Asked Questions about Buddypress Profile Visitors