Gift Buddypress Addons Security & Risk Analysis

wordpress.org/plugins/gift-buddypress-addons

Gift Buddypress Add-ons provide gift management functionality with BuddyPress plugin.

10 active installs v2.0.0 PHP + WP 4.3.1+ Updated Dec 29, 2017
buddypressbuddypress-giftsgiftgifts
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gift Buddypress Addons Safe to Use in 2026?

Generally Safe

Score 85/100

Gift Buddypress Addons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "gift-buddypress-addons" v2.0.0 plugin exhibits a generally good security posture with no recorded vulnerabilities or critical code signals. The absence of any CVEs, coupled with the fact that all AJAX handlers have authentication checks and there are no unprotected entry points, is a significant strength. The code analysis shows a healthy approach to external requests and file operations. However, there are areas for improvement. A notable concern is the percentage of SQL queries not using prepared statements, which could be a vector for SQL injection if input is not properly sanitized. Similarly, over half of the output is not properly escaped, posing a risk of cross-site scripting (XSS) vulnerabilities. The presence of a single unsanitized path in the taint analysis, even without a critical severity, warrants attention as it could be an indicator of a potential weakness. While the plugin is strong in its handling of AJAX requests and external interactions, the SQL and output escaping practices suggest potential vulnerabilities that could be exploited.

Key Concerns

  • SQL queries not using prepared statements
  • Unescaped output found
  • Taint analysis shows unsanitized path
Vulnerabilities
None known

Gift Buddypress Addons Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Gift Buddypress Addons Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Gift Buddypress Addons Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
2 prepared
Unescaped Output
11
13 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

40% prepared5 total queries

Output Escaping

54% escaped24 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
bga_send_gifts_content (buddypress-gift-addon.php:233)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Gift Buddypress Addons Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_bga_autocomplete_resultsbuddypress-gift-addon.php:27
noprivwp_ajax_bga_autocomplete_resultsbuddypress-gift-addon.php:28
authwp_ajax_bga_send_gift_ajax_callbackbuddypress-gift-addon.php:32
noprivwp_ajax_bga_send_gift_ajax_callbackbuddypress-gift-addon.php:33
WordPress Hooks 11
actionbp_setup_navbuddypress-gift-addon.php:22
actionwp_enqueue_scriptsbuddypress-gift-addon.php:26
filterbp_notifications_get_registered_componentsbuddypress-gift-addon.php:29
filterbp_notifications_get_notifications_for_userbuddypress-gift-addon.php:30
actionbp_activity_sent_giftbuddypress-gift-addon.php:31
actionplugins_loadedbuddypress-gift-addon.php:34
actionbp_template_contentbuddypress-gift-addon.php:148
actionbp_template_contentbuddypress-gift-addon.php:157
actioninitfunctions.php:8
actioninitfunctions.php:9
actioninitfunctions.php:10
Maintenance & Trust

Gift Buddypress Addons Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedDec 29, 2017
PHP min version
Downloads6K

Community Trust

Rating86/100
Number of ratings7
Active installs10
Developer Profile

Gift Buddypress Addons Developer Profile

Faiyaz Alam

7 plugins · 15K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
1468 days
View full developer profile
Detection Fingerprints

How We Detect Gift Buddypress Addons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gift-buddypress-addons/css/gift-bp-addons.css/wp-content/plugins/gift-buddypress-addons/js/jquery.auto-complete.js/wp-content/plugins/gift-buddypress-addons/js/gift-bp-addons.js
Script Paths
/wp-content/plugins/gift-buddypress-addons/js/jquery.auto-complete.js/wp-content/plugins/gift-buddypress-addons/js/gift-bp-addons.js
Version Parameters
gift-buddypress-addons/css/gift-bp-addons.css?ver=gift-buddypress-addons/js/jquery.auto-complete.js?ver=gift-buddypress-addons/js/gift-bp-addons.js?ver=

HTML / DOM Fingerprints

CSS Classes
gba-outer-containergiftbox-containergiftboxbga-outer-containerbga-modal-overlaybga-modal-contentbga-close-buttonbga-gift-image+8 more
Data Attributes
id="SendGiftForm"id="giftModal"id="bgamain"data-nonce="
JS Globals
bgamain
REST Endpoints
/wp-json/gift-buddypress-addons/v1/autocomplete
Shortcode Output
<div class="gba-outer-container"><div class="giftbox-container<div class="giftbox"<ul id="tabs">
FAQ

Frequently Asked Questions about Gift Buddypress Addons