BuddyPress Real Names Security & Risk Analysis

wordpress.org/plugins/buddypress-real-names

BuddyPress Real Names allows you to change the regular nickname displayed for a user to anything you want.

30 active installs v0.3.5 PHP + WP + Updated Feb 13, 2013
buddypressfirst-namefull-namelast-namenames
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BuddyPress Real Names Safe to Use in 2026?

Generally Safe

Score 85/100

BuddyPress Real Names has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "buddypress-real-names" plugin v0.3.5 exhibits a generally strong security posture based on the static analysis provided. The absence of identified dangerous functions, file operations, external HTTP requests, and SQL queries executed without prepared statements are positive indicators. Furthermore, the lack of any recorded CVEs, particularly critical or high severity ones, suggests a history of responsible development and maintenance concerning known vulnerabilities. This plugin has zero recorded vulnerabilities, and the last one was never recorded. There are no listed common vulnerability types and no critical or high vulnerabilities recorded.

However, there are significant concerns regarding output sanitization. With 18% of output properly escaped out of 11 total outputs, a substantial portion of the plugin's output is not being properly sanitized, creating a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly outputted without adequate escaping. Additionally, the complete absence of nonce checks and capability checks across all entry points, coupled with a lack of any taint analysis flows, could mask potential security weaknesses. While the attack surface appears minimal with 0 entry points, the lack of fundamental security checks on these potential entry points is a notable concern, as is the lack of taint analysis.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks
  • No capability checks
  • No taint analysis performed
Vulnerabilities
None known

BuddyPress Real Names Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BuddyPress Real Names Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

18% escaped11 total outputs
Attack Surface

BuddyPress Real Names Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_initbprn-admin.php:50
actionadmin_menubprn-admin.php:51
filterbp_get_the_profile_field_namebuddypress-real-names.php:130
filterbp_core_get_user_displaynamebuddypress-real-names.php:133
filterbp_get_member_namebuddypress-real-names.php:136
actionbp_pre_user_querybuddypress-real-names.php:137
actioninitbuddypress-real-names.php:140
actionbp_includeloader.php:35
filterplugin_action_linksloader.php:36
Maintenance & Trust

BuddyPress Real Names Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedFeb 13, 2013
PHP min version
Downloads10K

Community Trust

Rating60/100
Number of ratings1
Active installs30
Developer Profile

BuddyPress Real Names Developer Profile

grosbouff

16 plugins · 380 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BuddyPress Real Names

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/buddypress-real-names/css/buddypress-real-names.css/wp-content/plugins/buddypress-real-names/js/buddypress-real-names.js
Script Paths
/wp-content/plugins/buddypress-real-names/js/buddypress-real-names.js
Version Parameters
buddypress-real-names/css/buddypress-real-names.css?ver=buddypress-real-names/js/buddypress-real-names.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about BuddyPress Real Names