
BuddyPress Sitewide Featured Posts Security & Risk Analysis
wordpress.org/plugins/buddypress-sitewide-featured-postsThis is a BuddyPress plugin that allows you to select and display featured posts sitewide.
Is BuddyPress Sitewide Featured Posts Safe to Use in 2026?
Generally Safe
Score 85/100BuddyPress Sitewide Featured Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "buddypress-sitewide-featured-posts" plugin version 0.3 presents a mixed security profile. On the positive side, the static analysis reveals a very small attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that are not protected by authentication checks. The absence of file operations and external HTTP requests further limits potential attack vectors. However, several code signals raise concerns. The presence of the `create_function` is a notable risk as it can lead to arbitrary code execution if user-supplied input is passed to it. Furthermore, a significant portion of SQL queries are not using prepared statements, increasing the risk of SQL injection vulnerabilities. Critically, none of the 23 identified output points are properly escaped, which strongly suggests a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The plugin has no recorded vulnerability history, which is positive, but this may also be due to its limited usage or the fact that the identified code issues have not yet been exploited or discovered.
Key Concerns
- Use of create_function
- SQL queries not using prepared statements
- No output properly escaped
BuddyPress Sitewide Featured Posts Security Vulnerabilities
BuddyPress Sitewide Featured Posts Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
BuddyPress Sitewide Featured Posts Attack Surface
WordPress Hooks 10
Maintenance & Trust
BuddyPress Sitewide Featured Posts Maintenance & Trust
Maintenance Signals
Community Trust
BuddyPress Sitewide Featured Posts Alternatives
Post List Featured Image
post-list-featured-image
A plugin that adds the "Featured Image" column in admin posts and pages list.
WP Featured Soliloquy Sliders
wp-featured-soliloquy-sliders
Provides a metabox on posts and pages listing existing Soliloquy Sliders.
Featured Image Column Display
featured-image-column-display
A plugin that adds the "Featured Image" column in admin posts and pages list.
Now Featuring WordPress Widget
now-featuring
The Now Featuring Wordpress Widget allows you to showcase featured content from your posts or pages on your sidebar in multiple ways.
WP Featured Menus
wp-featured-menus
Provides a metabox on posts and pages listing existing WordPress Menus.
BuddyPress Sitewide Featured Posts Developer Profile
16 plugins · 380 total installs
How We Detect BuddyPress Sitewide Featured Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
featured-postsitem-avataritemitem-titleitem-contentitem-metawidget-errorid="featured-posts"class="item-list"