
BuddyPress Real Names Security & Risk Analysis
wordpress.org/plugins/buddypress-real-namesBuddyPress Real Names allows you to change the regular nickname displayed for a user to anything you want.
Is BuddyPress Real Names Safe to Use in 2026?
Generally Safe
Score 85/100BuddyPress Real Names has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "buddypress-real-names" plugin v0.3.5 exhibits a generally strong security posture based on the static analysis provided. The absence of identified dangerous functions, file operations, external HTTP requests, and SQL queries executed without prepared statements are positive indicators. Furthermore, the lack of any recorded CVEs, particularly critical or high severity ones, suggests a history of responsible development and maintenance concerning known vulnerabilities. This plugin has zero recorded vulnerabilities, and the last one was never recorded. There are no listed common vulnerability types and no critical or high vulnerabilities recorded.
However, there are significant concerns regarding output sanitization. With 18% of output properly escaped out of 11 total outputs, a substantial portion of the plugin's output is not being properly sanitized, creating a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly outputted without adequate escaping. Additionally, the complete absence of nonce checks and capability checks across all entry points, coupled with a lack of any taint analysis flows, could mask potential security weaknesses. While the attack surface appears minimal with 0 entry points, the lack of fundamental security checks on these potential entry points is a notable concern, as is the lack of taint analysis.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks
- No capability checks
- No taint analysis performed
BuddyPress Real Names Security Vulnerabilities
BuddyPress Real Names Code Analysis
Output Escaping
BuddyPress Real Names Attack Surface
WordPress Hooks 9
Maintenance & Trust
BuddyPress Real Names Maintenance & Trust
Maintenance Signals
Community Trust
BuddyPress Real Names Alternatives
Extended User Search In WP-Admin
extended-user-search-in-wp-admin
By default WordPress in WP-admin allows users to search only by username or email id.
Force First and Last Name as Display Name
force-first-last
Force the user field "display_name" to be set as the user's first and last name.
Enhanced User Search
enhanced-user-search
Effortlessly find users in WordPress! Search by first & last name, username, or email.
BuddyPress Usernames Only
buddypress-usernames-only
Override display names across your BuddyPress site with usernames.
First name Last name
first-name-and-last-name-on-registration-page
Adds First name and Last name to registration form.
BuddyPress Real Names Developer Profile
16 plugins · 380 total installs
How We Detect BuddyPress Real Names
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buddypress-real-names/css/buddypress-real-names.css/wp-content/plugins/buddypress-real-names/js/buddypress-real-names.js/wp-content/plugins/buddypress-real-names/js/buddypress-real-names.jsbuddypress-real-names/css/buddypress-real-names.css?ver=buddypress-real-names/js/buddypress-real-names.js?ver=