
Follow for bbPress Security & Risk Analysis
wordpress.org/plugins/follow-bbpressThe Follow for bbPress provides a users following system for bbPress.
Is Follow for bbPress Safe to Use in 2026?
Generally Safe
Score 85/100Follow for bbPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "follow-bbpress" v1.0 plugin exhibits a concerning security posture due to a large attack surface with a significant number of unprotected entry points. While the plugin demonstrates good practices in SQL query handling and a relatively high percentage of proper output escaping, the lack of authorization checks on 14 out of 15 AJAX handlers is a critical weakness. This means that any user, authenticated or not, could potentially interact with these handlers, leading to unintended actions or information disclosure.
The taint analysis reveals two flows with unsanitized paths, classified as high severity. This suggests that user-supplied data might be used in a way that could lead to path traversal or other file system-related vulnerabilities, despite no explicit file operations being flagged. The limited number of nonce checks (7) and capability checks (1) further exacerbates the risk, as these are fundamental security mechanisms for protecting against various types of attacks.
Currently, the plugin has no recorded vulnerability history, which is a positive indicator. However, this does not negate the present risks identified in the static and taint analysis. The plugin's strengths lie in its secure SQL implementation and mostly proper output escaping. Nevertheless, the high number of unprotected AJAX handlers and the identified unsanitized paths present significant security concerns that require immediate attention.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized paths in taint analysis
- Low number of capability checks
- Moderate percentage of unescaped output
Follow for bbPress Security Vulnerabilities
Follow for bbPress Release Timeline
Follow for bbPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Follow for bbPress Attack Surface
AJAX Handlers 14
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Follow for bbPress Maintenance & Trust
Maintenance Signals
Community Trust
Follow for bbPress Alternatives
One User Avatar | User Profile Picture
one-user-avatar
Use any image from your WordPress Media Library as a custom user avatar or user profile picture. Add your own Default Avatar.
User Access Shortcodes
user-access-shortcodes
The simplest way of controlling who sees what in your posts/pages. Restrict content to logged in users only (or guests, or by roles) with simple short …
User Shortcodes
user-shortcodes
Add a simple list of shortcodes to WordPress in order to display the current user information.
CBX User Online & Last Login
cbxuseronline
Shows online users based on cookie for guest and session for registered user. It also records the last login of user.
ForumWP – Forum & Discussion Board
forumwp
Add a forum to your website with ForumWP.
Follow for bbPress Developer Profile
13 plugins · 40 total installs
How We Detect Follow for bbPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/follow-bbpress/css/style.css/wp-content/plugins/follow-bbpress/js/script.js/wp-content/plugins/follow-bbpress/js/script.jsfollow-bbpress/css/style.css?ver=follow-bbpress/js/script.js?ver=HTML / DOM Fingerprints
follow_box_containerbbpf_followersbbpf_followers_linkbbpf_followingbbpf_following_linkbbpf_follower_listbbpf_following_listpopup-inner+9 moredata-popup-opendata-popupdata-user_iddata-item_limitdata-popup-closebbpf_ajax_urlbbpf_nonce/wp-json/bbpf-rest/v1