
Custom Tabs for BuddyPress Security & Risk Analysis
wordpress.org/plugins/custom-tabs-for-buddypressAdd custom tabs to BuddyPress user profiles with role-based visibility and shortcode content, managed from the admin panel. Requires BuddyPress.
Is Custom Tabs for BuddyPress Safe to Use in 2026?
Generally Safe
Score 100/100Custom Tabs for BuddyPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The custom-tabs-for-buddypress plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events, along with zero identified dangerous functions and file operations, significantly limits its attack surface and potential for direct exploitation. The plugin also demonstrates good practices by using prepared statements for all SQL queries and a high percentage of properly escaped output. Furthermore, the lack of any recorded vulnerabilities in its history suggests a history of stable and secure development.
However, a notable concern arises from the complete absence of nonce checks and capability checks. While the current attack surface is zero, this represents a significant oversight. Should any entry points be introduced in future versions without proper authentication and authorization mechanisms, the plugin would be highly vulnerable to various attacks such as CSRF and unauthorized actions. The taint analysis also reporting zero flows is positive, but the lack of any analysis performed (total flows analyzed: 0) means this is not a confirmation of no taint, but rather an indication that no taint analysis was conducted.
In conclusion, while the current implementation of custom-tabs-for-buddypress v1.0.0 appears secure due to its limited entry points and good coding practices for SQL and output handling, the complete lack of security checks for potential future entry points is a critical weakness. The plugin's vulnerability history is clean, but this is largely due to the limited functionality exposed in this version. Future development must address the implementation of proper nonce and capability checks to maintain security.
Key Concerns
- Missing nonce checks
- Missing capability checks
- No taint analysis performed
Custom Tabs for BuddyPress Security Vulnerabilities
Custom Tabs for BuddyPress Code Analysis
Output Escaping
Custom Tabs for BuddyPress Attack Surface
WordPress Hooks 4
Maintenance & Trust
Custom Tabs for BuddyPress Maintenance & Trust
Maintenance Signals
Community Trust
Custom Tabs for BuddyPress Alternatives
BP XProfile Shortcode
bp-xprofile-shortcode
Adds Shortcode for BuddyPress XProfile data
Custom Profile Filters for BuddyPress
buddypress-custom-profile-filters
Allows users to take control of the way that the links in their Buddypress profiles are handled.
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress
youzify
The best BuddyPress plugin for building online communities, user profile, social networks, and membership sites on WordPress with tons of features.
BuddyPress Xprofile Custom Field Types
bp-xprofile-custom-field-types
Buddypress Xprofile Custom Field Types adds extra custom profile fields to BuddyPress. Field types are: Birthdate, Email, Url etc.
BuddyPress Activity Shortcode
bp-activity-shortcode
BuddyPress Activity shortcode plugin allows you to insert BuddyPress activity stream on any page/post using shortcode.
Custom Tabs for BuddyPress Developer Profile
2 plugins · 110 total installs
How We Detect Custom Tabs for BuddyPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapform-tableid="custom_bp_tabs_0_name"name="custom_bp_tabs[0][name]"id="custom_bp_tabs_0_slug"name="custom_bp_tabs[0][slug]"id="custom_bp_tabs_0_shortcode"name="custom_bp_tabs[0][shortcode]"+18 moredo_shortcode