
Buddypress Who clicked at my Profile? Security & Risk Analysis
wordpress.org/plugins/buddypress-who-clicked-at-my-profileThis plugin will notify your members about other members that visited their profile. This plugin also provides a widget that shows last profile visito …
Is Buddypress Who clicked at my Profile? Safe to Use in 2026?
Generally Safe
Score 85/100Buddypress Who clicked at my Profile? has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "buddypress-who-clicked-at-my-profile" plugin v3.6 exhibits a concerning security posture due to several critical weaknesses identified in the static analysis. While the plugin boasts no known CVEs and utilizes prepared statements for its SQL queries, these positive aspects are overshadowed by significant vulnerabilities. The presence of two instances of the `unserialize` function, combined with a complete lack of output escaping, creates a high risk of cross-site scripting (XSS) and remote code execution (RCE) vulnerabilities. The unprotected AJAX handler further exacerbates this, as it provides an unauthenticated entry point that could be leveraged to trigger these dangerous functions. The absence of nonce checks and capability checks on this handler means any unauthenticated user could potentially exploit these flaws. The plugin's history of no reported vulnerabilities might suggest a lack of targeted attacks or that previous versions were not thoroughly audited, but it does not negate the immediate risks presented by the current codebase.
Key Concerns
- Unprotected AJAX handler
- Dangerous function 'unserialize' used
- Output escaping completely missing
- No nonce checks
- No capability checks
Buddypress Who clicked at my Profile? Security Vulnerabilities
Buddypress Who clicked at my Profile? Code Analysis
Dangerous Functions Found
Output Escaping
Buddypress Who clicked at my Profile? Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Buddypress Who clicked at my Profile? Maintenance & Trust
Maintenance Signals
Community Trust
Buddypress Who clicked at my Profile? Alternatives
BuddyPress Edit Activity
buddypress-edit-activity
BuddyPress Edit Activity allows your members to edit their activity posts on the front-end of your BuddyPress-powered site.
Advanced XProfile Fields for BuddyPress
advanced-xprofile-fields-for-buddypress
Enhance your BuddyPress profile fields with Advanced XProfile Fields for BuddyPress. Manage fields labels, validation and show fields in admin.
Buddypress Xprofile Fields Custom Css Classes
bp-xprofile-fields-custom-css-classes
Add custom classes to xprofile fields for ease of styling.
MIF BP Customizer
mif-bp-customizer
Buddypress features extension plugin for creation of social network site.
Profiles Manager
profiles-manager-for-buddypress
This plugin is designed to help you monetize your social network by hiding the premium profile fields from non-paying members.
Buddypress Who clicked at my Profile? Developer Profile
5 plugins · 290 total installs
How We Detect Buddypress Who clicked at my Profile?
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buddypress-who-clicked-at-my-profile/buddypress-wcamp-widget.css/wp-content/plugins/buddypress-who-clicked-at-my-profile/buddypress-wcamp-widget.js/wp-content/plugins/buddypress-who-clicked-at-my-profile/js/jquery.countdown.min.js/wp-content/plugins/buddypress-who-clicked-at-my-profile/js/script.js/wp-content/plugins/buddypress-who-clicked-at-my-profile/buddypress-wcamp-widget.css?ver=/wp-content/plugins/buddypress-who-clicked-at-my-profile/buddypress-wcamp-widget.js?ver=/wp-content/plugins/buddypress-who-clicked-at-my-profile/js/jquery.countdown.min.js?ver=/wp-content/plugins/buddypress-who-clicked-at-my-profile/js/script.js?ver=HTML / DOM Fingerprints
buddypresswcampbuddypresswcamp_visitors<!-- buddypresswcamp --><!-- buddypresswcamp_visitors -->rel="user_"buddypresswcampbp_wcamp_data<p>Your profile has not been visited yet by another member of the community.</p><p>Please log in to view the visitors of your profile</p>