[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$flh2Hca2eH5NWYBJvXYakhwnNEZR9us5EqnmWcnp0Mpc":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":23,"download_link":24,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28,"vulnerabilities":29,"developer":30,"crawl_stats":27,"alternatives":36,"analysis":128,"fingerprints":238},"buddypress-who-clicked-at-my-profile","Buddypress Who clicked at my Profile?","3.6","quan_flo","https:\u002F\u002Fprofiles.wordpress.org\u002Fquan_flo\u002F","\u003Cp>\u003Cstrong>Do you want to increase your buddypress user’s interaction?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Tell them if other visited their profile!\u003C\u002Fp>\n\u003Cp>This plugin will notify your members about other members that visited their profile via buddypress notification system.\u003Cbr \u002F>\nThis plugin also provides a widget that shows last profile visitors for the logged in user.\u003Cbr \u002F>\nThis plugin provides a shortcode that can be used anywhere to display the logged in user’s visitors\u003C\u002Fp>\n\u003Cp>Shortcode usage:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>[buddypresswcamp_show_visits]\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Use Parameter to show avatars insted of links or configure how many last visitors should be shown.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>[buddypresswcamp_show_visits showAvatars=1 amount=5]\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>If you use bbpress \u003C 2.6 please apply the changes described there: https:\u002F\u002Fbbpress.trac.wordpress.org\u002Fticket\u002F2779 to get the notifications working\u003C\u002Fp>\n\u003Cp>\u003Cstrong>More about me and my plugins\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Since the year 1999 I do administration, customizing and programming for several forums, communities and social networks. In the year 2013 I switched from another PHP framework to WordPress.\u003Cbr \u002F>\nBecause not all plugins I’d like to have exist already I wrote some own plugins and I think I’ll continue to do so.\u003C\u002Fp>\n\u003Cp>If you have the scope at forums or social networks my other modules might also be interesting for you. \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fsearch.php?q=quan_flo\" title=\"ifs-net \u002F quan_flo WordPress Plugins\" rel=\"ugc\">Just take a look at my WordPress Profile to see all my Plugins.\u003C\u002Fa> Use them and if my work helps you to save time, earn money or just makes you happy feel free to donate – Thanks. The donation link can be found at the right sidebar next to this text.\u003C\u002Fp>\n","This plugin will notify your members about other members that visited their profile. This plugin also provides a widget that shows last profile visito &hellip;",40,15155,98,15,"2016-07-25T18:23:00.000Z","4.7.32","4.2","",[20,21,22],"buddypress","profile","social-network","http:\u002F\u002Fifs-net.de","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbuddypress-who-clicked-at-my-profile.zip",85,0,null,"2026-03-15T15:16:48.613Z",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":31,"total_installs":32,"avg_security_score":25,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},5,290,30,84,"2026-04-04T15:16:09.444Z",[37,59,78,92,112],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":45,"downloaded":46,"rating":47,"num_ratings":48,"last_updated":49,"tested_up_to":50,"requires_at_least":51,"requires_php":18,"tags":52,"homepage":57,"download_link":58,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"buddypress-edit-activity","BuddyPress Edit Activity","1.1.1","Syed Balkhi","https:\u002F\u002Fprofiles.wordpress.org\u002Fsmub\u002F","\u003Cp>Let your BuddyPress members edit their activity posts and replies on the front-end of the site. You can even set a time limit for how long activity posts should remain editable.\u003C\u002Fp>\n\u003Cp>Just activate the plugin, and every activity post and reply will become editable, styled automatically by BuddyPress to fit with your theme.\u003C\u002Fp>\n","BuddyPress Edit Activity allows your members to edit their activity posts on the front-end of your BuddyPress-powered site.",900,75058,92,17,"2020-04-23T13:56:00.000Z","5.4.19","3.8",[53,20,54,55,56],"activity","messaging","profiles","social-networking","https:\u002F\u002Fwww.buddyboss.com\u002Fproduct\u002Fbuddypress-edit-activity\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbuddypress-edit-activity.1.1.1.zip",{"slug":60,"name":61,"version":62,"author":63,"author_profile":64,"description":65,"short_description":66,"active_installs":67,"downloaded":68,"rating":34,"num_ratings":31,"last_updated":69,"tested_up_to":50,"requires_at_least":70,"requires_php":71,"tags":72,"homepage":76,"download_link":77,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"advanced-xprofile-fields-for-buddypress","Advanced XProfile Fields for BuddyPress","1.0.4.2","SuitePlugins","https:\u002F\u002Fprofiles.wordpress.org\u002Fsuiteplugins\u002F","\u003Cp>Advanced XProfile Fields for BuddyPress creates a way to enhance your BuddyPress profile fields.\u003C\u002Fp>\n\u003Ch4>Take control of all your field labels\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Create 1 profile field and change the label shown on Registration, Profile Edit, My Profile, Other User Profile screen\u003C\u002Fli>\n\u003Cli>Add a label for user listing screen\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Validate fields on Profile Edit\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Set Character Limits\u003C\u002Fli>\n\u003Cli>Set Minimum Character Requirements\u003C\u002Fli>\n\u003Cli>Text Format\u003Cbr \u002F>\n** Force text formats – Alphanumeric, Alpha, Email and URL\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Additional Options\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Hide field on registration page\u003C\u002Fli>\n\u003Cli>Make a field non-editable after a user has saved entry. Perfect for field like Gender, Title etc\u003C\u002Fli>\n\u003Cli>Show fields in admin. Show the profile field in the user’s admin list.\u003C\u002Fli>\n\u003C\u002Ful>\n","Enhance your BuddyPress profile fields with Advanced XProfile Fields for BuddyPress. Manage fields labels, validation and show fields in admin.",100,13299,"2020-04-26T18:57:00.000Z","3.2","5.3",[20,73,74,75,22],"buddypress-groups","buddypress-profile-field","groups","http:\u002F\u002Fsuiteplugins.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fadvanced-xprofile-fields-for-buddypress.zip",{"slug":79,"name":80,"version":81,"author":82,"author_profile":83,"description":84,"short_description":85,"active_installs":86,"downloaded":87,"rating":26,"num_ratings":26,"last_updated":88,"tested_up_to":16,"requires_at_least":70,"requires_php":18,"tags":89,"homepage":90,"download_link":91,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"bp-xprofile-fields-custom-css-classes","Buddypress Xprofile Fields Custom Css Classes","1.0","codepixlabs","https:\u002F\u002Fprofiles.wordpress.org\u002Fcodepixlabs\u002F","\u003Cp>Buddypress Xprofile Fields Custom Css Classes allows to add classes to xprofile fields for ease of styling.\u003C\u002Fp>\n\u003Ch4>Gives more control for frontend designers\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Add single or multiple classes to each field\u003C\u002Fli>\n\u003Cli>Group fields based on classes\u003C\u002Fli>\n\u003Cli>Extremely light \u003C 5kb\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Eases process of css framework support\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Buddypress forms ( register \u002F profile edit ) do not support any css frameworks out of the box\u003C\u002Fli>\n\u003Cli>This plugins makes it easy to style forms as per any css framworks, as it provide ability to add css classes for each field\u003C\u002Fli>\n\u003C\u002Ful>\n","Add custom classes to xprofile fields for ease of styling.",20,1931,"2017-04-24T11:07:00.000Z",[20,73,74,75,22],"http:\u002F\u002Fcodepixlabs.com\u002Fplugins\u002Fbuddypress-xprofile-fields-custom-css-classes","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbp-xprofile-fields-custom-css-classes.zip",{"slug":93,"name":94,"version":95,"author":96,"author_profile":97,"description":98,"short_description":99,"active_installs":100,"downloaded":101,"rating":67,"num_ratings":102,"last_updated":18,"tested_up_to":103,"requires_at_least":104,"requires_php":18,"tags":105,"homepage":109,"download_link":110,"security_score":67,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":111},"mif-bp-customizer","MIF BP Customizer","1.0.0","asergeev34","https:\u002F\u002Fprofiles.wordpress.org\u002Fasergeev34\u002F","\u003Cp>Buddypress features extension plugin for creation of social network site.\u003Cbr \u002F>\nIt is oriented on work with social networking plugin BuddyPress.\u003C\u002Fp>\n\u003Cp>Adds features:\u003C\u002Fp>\n\u003Cp>Activity feed\u003C\u002Fp>\n\u003Cp>Special activity feed. Changes the appearance and behavior of the activity feed on users’ pages (on personal page – “Whole feed”, on other users’ pages – only their activity). Allows to use content blocking tools.\u003C\u002Fp>\n\u003Cp>Post types of activity feed. Allows to specify activity types, which should be displayed in user’s feed (“Special activity feed” option is required).\u003C\u002Fp>\n\u003Cp>User blocking. Allows to maintain a list of users, whose information is blocked in your activity feed (“Special activity feed” option is required).\u003C\u002Fp>\n\u003Cp>Site behavior\u003C\u002Fp>\n\u003Cp>Profile as a homepage. Set user profile as his home page.\u003C\u002Fp>\n\u003Cp>Profile privacy. Allow users to limit access to their profiles.\u003C\u002Fp>\n\u003Cp>Subscribers. Enable subscription option for user updates (subscription = one-way friendship).\u003C\u002Fp>\n\u003Cp>Notifications. Advanced notification mode.\u003C\u002Fp>\n\u003Cp>Pop-up messages. Mechanism of pop-up messages (echo-server configuration is required).\u003C\u002Fp>\n\u003Cp>Documents. Creation of files and documents collections on users’ and groups’ pages. Files and documents publication in the activity feed.\u003C\u002Fp>\n\u003Cp>Dialogues (experimentally\u002Fis in a test mode). Simple and convenient dialogues instead of the standard system of private messages (experimentally\u002Fis in a test mode; echo-server configuration is required).\u003C\u002Fp>\n\u003Cp>Background image. Allow to use custom image as a background for user profile or group.\u003C\u002Fp>\n\u003Cp>Group address. Allow to change the group address in its settings and at creation.\u003C\u002Fp>\n\u003Cp>«Like» button. «Like» button for posts in the activity feed.\u003C\u002Fp>\n\u003Cp>«Repost» button. Second publication (repost) of posts in the activity feed.\u003C\u002Fp>\n\u003Cp>«Favorite», «Delete» buttons. Special «Favorite», «Delete» buttons (as «Like» and «Repost» button)\u003C\u002Fp>\n\u003Cp>Visual elements\u003C\u002Fp>\n\u003Cp>Site member widget. Fast and simple widget of site members avatars.\u003C\u002Fp>\n\u003Cp>Group widget. Fast and simple widget of group avatars.\u003C\u002Fp>\n","Buddypress features extension plugin for creation of social network site.",10,1691,1,"4.9.29","4.8",[20,106,107,108,22],"like","private-profile","repost","https:\u002F\u002Fgithub.com\u002Falexey-sergeev\u002Fmif-bp-customizer","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmif-bp-customizer.zip","2026-03-15T10:48:56.248Z",{"slug":113,"name":114,"version":115,"author":116,"author_profile":117,"description":118,"short_description":119,"active_installs":100,"downloaded":120,"rating":67,"num_ratings":102,"last_updated":121,"tested_up_to":122,"requires_at_least":123,"requires_php":18,"tags":124,"homepage":126,"download_link":127,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"profiles-manager-for-buddypress","Profiles Manager","1.6","elbuntu","https:\u002F\u002Fprofiles.wordpress.org\u002Felbuntu\u002F","\u003Cp>Profiles Manager is designed to help you monetize your social network by hiding the premium profile fields from non-paying members. This plugin\u003Cbr \u002F>\nworks with any kind of payment system in place but is tested with s2member.\u003C\u002Fp>\n\u003Cp>Features:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Hide BuddyPress Profile Groups to certain members\u003C\u002Fli>\n\u003Cli>Easy to use UI\u003C\u002Fli>\n\u003Cli>Create upgrade account menu item on free members profiles.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Removing the plugin\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Deactivate The Plugin \u003C\u002Fli>\n\u003Cli>Replace bp_pm_group_tabs(); with bp_profile_group_tabs();\u003C\u002Fli>\n\u003C\u002Ful>\n","This plugin is designed to help you monetize your social network by hiding the premium profile fields from non-paying members.",4465,"2016-02-25T13:24:00.000Z","3.4.2","2.8",[20,21,125,22],"social","http:\u002F\u002Felbuntu.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fprofiles-manager-for-buddypress.zip",{"attackSurface":129,"codeSignals":178,"taintFlows":220,"riskAssessment":221,"analyzedAt":237},{"hooks":130,"ajaxHandlers":165,"restRoutes":171,"shortcodes":172,"cronEvents":176,"entryPointCount":177,"unprotectedCount":102},[131,137,141,144,148,153,157,161],{"type":132,"name":133,"callback":134,"file":135,"line":136},"action","bp_include","bpwcamp_init","buddypress-who-clicked-at-my-profile.php",23,{"type":132,"name":138,"callback":139,"file":140,"line":31},"init","buddypresswcamp_load_textdomain","plugin.php",{"type":132,"name":142,"callback":143,"file":140,"line":14},"bp_before_member_header","buddypresswcamp_action",{"type":132,"name":145,"callback":146,"file":140,"line":147},"widgets_init","buddypresswcamp_widget_showMyVisitors",153,{"type":149,"name":150,"callback":151,"priority":102,"file":140,"line":152},"filter","bp_notifications_get_registered_components","buddypresswcamp_notification_get_registered_components",232,{"type":149,"name":154,"callback":155,"priority":100,"file":140,"line":156},"bp_notifications_get_notifications_for_user","buddypresswcamp_format_buddypress_notifications",249,{"type":132,"name":158,"callback":159,"file":140,"line":160},"all_admin_notices","buddypresswcamp_upgrade_donation_notification",251,{"type":132,"name":162,"callback":163,"file":140,"line":164},"admin_enqueue_scripts","buddypresswcamp_enqueue_scripts",274,[166],{"action":167,"nopriv":168,"callback":169,"hasNonce":168,"hasCapCheck":168,"file":140,"line":170},"bpwcamp_notification",false,"buddypresswcamp_remove_update_notification",280,[],[173],{"tag":174,"callback":174,"file":140,"line":175},"buddypresswcamp_show_visits",83,[],2,{"dangerousFunctions":179,"sqlUsage":186,"outputEscaping":188,"fileOperations":26,"externalRequests":26,"nonceChecks":26,"capabilityChecks":26,"bundledLibraries":219},[180,184],{"fn":181,"file":140,"line":182,"context":183},"unserialize",33,"$trackingList = unserialize($meta);",{"fn":181,"file":140,"line":185,"context":183},107,{"prepared":26,"raw":26,"locations":187},[],{"escaped":26,"rawEcho":189,"locations":190},16,[191,194,196,198,200,202,204,205,206,208,209,211,213,215,216,217],{"file":140,"line":192,"context":193},174,"raw output",{"file":140,"line":195,"context":193},178,{"file":140,"line":197,"context":193},180,{"file":140,"line":199,"context":193},181,{"file":140,"line":201,"context":193},208,{"file":140,"line":203,"context":193},209,{"file":140,"line":203,"context":193},{"file":140,"line":203,"context":193},{"file":140,"line":207,"context":193},212,{"file":140,"line":207,"context":193},{"file":140,"line":210,"context":193},213,{"file":140,"line":212,"context":193},216,{"file":140,"line":214,"context":193},217,{"file":140,"line":214,"context":193},{"file":140,"line":214,"context":193},{"file":140,"line":218,"context":193},262,[],[],{"summary":222,"deductions":223},"The \"buddypress-who-clicked-at-my-profile\" plugin v3.6 exhibits a concerning security posture due to several critical weaknesses identified in the static analysis. While the plugin boasts no known CVEs and utilizes prepared statements for its SQL queries, these positive aspects are overshadowed by significant vulnerabilities. The presence of two instances of the `unserialize` function, combined with a complete lack of output escaping, creates a high risk of cross-site scripting (XSS) and remote code execution (RCE) vulnerabilities. The unprotected AJAX handler further exacerbates this, as it provides an unauthenticated entry point that could be leveraged to trigger these dangerous functions. The absence of nonce checks and capability checks on this handler means any unauthenticated user could potentially exploit these flaws. The plugin's history of no reported vulnerabilities might suggest a lack of targeted attacks or that previous versions were not thoroughly audited, but it does not negate the immediate risks presented by the current codebase.",[224,227,230,232,234],{"reason":225,"points":226},"Unprotected AJAX handler",8,{"reason":228,"points":229},"Dangerous function 'unserialize' used",7,{"reason":231,"points":226},"Output escaping completely missing",{"reason":233,"points":229},"No nonce checks",{"reason":235,"points":236},"No capability checks",6,"2026-03-16T22:16:42.148Z",{"wat":239,"direct":252},{"assetPaths":240,"generatorPatterns":245,"scriptPaths":246,"versionParams":247},[241,242,243,244],"\u002Fwp-content\u002Fplugins\u002Fbuddypress-who-clicked-at-my-profile\u002Fbuddypress-wcamp-widget.css","\u002Fwp-content\u002Fplugins\u002Fbuddypress-who-clicked-at-my-profile\u002Fbuddypress-wcamp-widget.js","\u002Fwp-content\u002Fplugins\u002Fbuddypress-who-clicked-at-my-profile\u002Fjs\u002Fjquery.countdown.min.js","\u002Fwp-content\u002Fplugins\u002Fbuddypress-who-clicked-at-my-profile\u002Fjs\u002Fscript.js",[],[],[248,249,250,251],"\u002Fwp-content\u002Fplugins\u002Fbuddypress-who-clicked-at-my-profile\u002Fbuddypress-wcamp-widget.css?ver=","\u002Fwp-content\u002Fplugins\u002Fbuddypress-who-clicked-at-my-profile\u002Fbuddypress-wcamp-widget.js?ver=","\u002Fwp-content\u002Fplugins\u002Fbuddypress-who-clicked-at-my-profile\u002Fjs\u002Fjquery.countdown.min.js?ver=","\u002Fwp-content\u002Fplugins\u002Fbuddypress-who-clicked-at-my-profile\u002Fjs\u002Fscript.js?ver=",{"cssClasses":253,"htmlComments":256,"htmlAttributes":259,"restEndpoints":261,"jsGlobals":262,"shortcodeOutput":264},[254,255],"buddypresswcamp","buddypresswcamp_visitors",[257,258],"\u003C!-- buddypresswcamp -->","\u003C!-- buddypresswcamp_visitors -->",[260],"rel=\"user_\"",[],[254,263],"bp_wcamp_data",[265,266],"\u003Cp>Your profile has not been visited yet by another member of the community.\u003C\u002Fp>","\u003Cp>Please log in to view the visitors of your profile\u003C\u002Fp>"]