
Buoy Security & Risk Analysis
wordpress.org/plugins/buoyA community-based crisis response system. Buoy is a private, enhanced, cop-free alternative to 112 or 911.
Is Buoy Safe to Use in 2026?
Generally Safe
Score 85/100Buoy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "buoy" plugin exhibits a generally strong security posture with no recorded vulnerabilities and robust practices in its code. The static analysis indicates a very small attack surface with zero unprotected entry points across AJAX handlers, REST API routes, shortcodes, and cron events. SQL queries are exclusively handled with prepared statements, and a high percentage of output is properly escaped, indicating good defense against common injection and XSS vulnerabilities. The presence of nonces and capability checks further strengthens its security. However, the static analysis does reveal a concerning signal: the presence of dangerous functions like `system` and `shell_exec` within the code. While taint analysis did not reveal exploitable flows, the mere presence of these functions is a significant risk factor. Additionally, two taint flows with unsanitized paths were identified, though without critical or high severity. The complete lack of historical vulnerabilities is a positive indicator of past development practices. Despite the absence of known CVEs, the discovery of dangerous functions warrants caution and further investigation.
Key Concerns
- Dangerous functions (system, shell_exec) present
- Flows with unsanitized paths found
Buoy Security Vulnerabilities
Buoy Release Timeline
Buoy Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Buoy Attack Surface
WordPress Hooks 52
Maintenance & Trust
Buoy Maintenance & Trust
Maintenance Signals
Community Trust
Buoy Alternatives
SpeakOut! Email Petitions
speakout
SpeakOut! Email Petitions makes it easy to add petitions to your website and rally your community to Speak Out about a cause by using direct action.
Petitioner
petitioner
Create, target, and track high-impact petitions with Petitioner: automate delivery to decision-makers, manage approvals, and export rich submission da …
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
ultimate-member
Membership & community plugin with user profiles, registration & login, member directories, content restriction, user roles and much more.
BuddyPress
buddypress
Get together safely, in your own way, in WordPress.
Ultimate Member – reCAPTCHA
um-recaptcha
Stop bots on your registration & login forms with Google reCAPTCHA
Buoy Developer Profile
15 plugins · 2K total installs
How We Detect Buoy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buoy/build/css/buoy.css/wp-content/plugins/buoy/build/js/buoy.js/wp-content/plugins/buoy/build/js/buoy.jsbuoy/build/css/buoy.css?ver=buoy/build/js/buoy.js?ver=HTML / DOM Fingerprints
buoy-notification-settingsbuoy-user-settingsbuoy-team-settingsbuoy-alert-settingsbuoy-dashboard-widgetdata-buoy-notification-settingsdata-buoy-user-settingsdata-buoy-team-settingsdata-buoy-alert-settingsbuoy_admin_ajax_urlbuoy_user_settingsbuoy_notification_settingsbuoy_team_settingsbuoy_alert_settings/wp-json/buoy/v1/notifications/wp-json/buoy/v1/users/wp-json/buoy/v1/teams/wp-json/buoy/v1/alerts