
Author: Simon Goodchild Security & Risk Analysis
wordpress.org/plugins/hts-display-active-membersDisplays most recently logged in members and optionally link to Private Message if logged in. Requires BuddyPress.
Is Author: Simon Goodchild Safe to Use in 2026?
Generally Safe
Score 85/100Author: Simon Goodchild has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The hts-display-active-members plugin version 0.2 appears to have a generally good security posture based on the provided static analysis. There are no identified dangerous functions, file operations, external HTTP requests, or external HTTP requests. All identified output is properly escaped, and the plugin doesn't bundle any external libraries, which is a positive sign. The SQL queries, while present, show a reasonable usage of prepared statements.
However, there are significant areas for improvement. The lack of any nonce or capability checks across all entry points, including the shortcode, is a major concern. This absence of authentication and authorization checks means that any user, even unauthenticated ones, could potentially interact with the plugin's functionality, leading to unexpected behavior or even denial-of-service if the shortcode has resource-intensive operations. The vulnerability history also indicates no recorded vulnerabilities, which is positive, but this could also be a result of limited testing or analysis rather than inherently secure code, especially given the identified lack of security controls.
In conclusion, while the plugin avoids common pitfalls like dangerous functions and unescaped output, the complete absence of authentication and authorization mechanisms on its sole entry point (the shortcode) presents a substantial security risk. This oversight needs to be addressed to ensure the plugin's secure operation.
Key Concerns
- No capability checks found
- No nonce checks found
Author: Simon Goodchild Security Vulnerabilities
Author: Simon Goodchild Release Timeline
Author: Simon Goodchild Code Analysis
SQL Query Safety
Author: Simon Goodchild Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Author: Simon Goodchild Maintenance & Trust
Maintenance Signals
Community Trust
Author: Simon Goodchild Alternatives
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts
post-carousel
Display posts, pages, and taxonomies in beautiful carousel, slider, and grid layouts with advanced filtering. Customizable, Developer-friendly.
WP Latest Posts
wp-latest-posts
Load your content from posts, page, tags or custom post type and display it anywhere in WordPress including in Gutenberg editor
BP Profile Search
bp-profile-search
Member search and member directories for BuddyPress and the BuddyBoss Platform.
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress
youzify
The best BuddyPress plugin for building online communities, user profile, social networks, and membership sites on WordPress with tons of features.
PE Recent Posts
pe-recent-posts
The simple plugin that allows you to display image slides with title, description and read more linked to posts from selected category.
Author: Simon Goodchild Developer Profile
2 plugins · 10 total installs
How We Detect Author: Simon Goodchild
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hts-display-active-members/hts-display-members.cssHTML / DOM Fingerprints
lastactive<ul id="hts_displaymembers" style="list-style-type:none"><li style="overflow: hidden"><a href="<h2><a href="<span class="lastactive">