
membersDirectory for bbPress Security & Risk Analysis
wordpress.org/plugins/gd-members-directory-for-bbpressAdd a forum members directory page into bbPress powered forums, including members filtering and additional widgets for listing members in the sidebar.
Is membersDirectory for bbPress Safe to Use in 2026?
Generally Safe
Score 100/100membersDirectory for bbPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "gd-members-directory-for-bbpress" v3.0 exhibits a generally strong security posture based on the provided static analysis. There are no identified critical or high severity taint flows, no direct SQL injection risks due to all queries using prepared statements, and no external HTTP requests or file operations that could be exploited. The absence of known vulnerabilities in its history is also a positive indicator, suggesting a history of secure development or prompt patching.
However, there are notable areas of concern that temper this otherwise positive outlook. The complete lack of nonce checks and capability checks across all entry points represents a significant security weakness. While the attack surface is reported as zero entry points, this analysis might be incomplete if the reported zero entry points doesn't fully account for all potential interaction vectors. Furthermore, the fact that only 70% of output is properly escaped indicates that approximately 30% of output might be vulnerable to Cross-Site Scripting (XSS) attacks. This is a considerable percentage and could lead to serious security incidents if user-supplied data is not adequately sanitized before display.
In conclusion, while the plugin avoids common pitfalls like raw SQL and critical taint issues, the absence of fundamental security controls like nonce and capability checks, combined with a significant portion of unescaped output, presents a tangible risk. These weaknesses require careful attention to mitigate potential XSS and authorization bypass vulnerabilities, even if the current attack surface appears small.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Significant unescaped output (30%)
membersDirectory for bbPress Security Vulnerabilities
membersDirectory for bbPress Code Analysis
SQL Query Safety
Output Escaping
membersDirectory for bbPress Attack Surface
WordPress Hooks 5
Maintenance & Trust
membersDirectory for bbPress Maintenance & Trust
Maintenance Signals
Community Trust
membersDirectory for bbPress Alternatives
powerSearch for bbPress
gd-power-search-for-bbpress
Enhanced and powerful search for bbPress powered forums, with options to filter results by various criteria.
One User Avatar | User Profile Picture
one-user-avatar
Use any image from your WordPress Media Library as a custom user avatar or user profile picture. Add your own Default Avatar.
AyeCode Connect
ayecode-connect
Use this service plugin to easily activate any of our products, open a support ticket and view documentation all from your wp-admin!
BP Profile Search
bp-profile-search
Member search and member directories for BuddyPress and the BuddyBoss Platform.
GD bbPress Attachments
gd-bbpress-attachments
Implement attachments upload to the topics and replies in bbPress plugin through a media library and add additional forum-based controls.
membersDirectory for bbPress Developer Profile
17 plugins · 12K total installs
How We Detect membersDirectory for bbPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gd-members-directory-for-bbpress/css/members.css/wp-content/plugins/gd-members-directory-for-bbpress/css/members-rtl.cssHTML / DOM Fingerprints
bbp-members-directoryforum-members-directorydata-members-directory-idgdmed_settings_data[gd_members_directory][gd_members_directory filter='all'][gd_members_directory filter='online']