
Invite Anyone Security & Risk Analysis
wordpress.org/plugins/invite-anyoneMakes BuddyPress's invitation features more powerful.
Is Invite Anyone Safe to Use in 2026?
Mostly Safe
Score 83/100Invite Anyone is generally safe to use though it hasn't been updated recently. 6 past CVEs were resolved. Keep it updated.
The "invite-anyone" plugin v1.4.10 presents a mixed security posture. On the positive side, the static analysis shows a high percentage of properly escaped outputs (95%), a good usage of prepared statements for SQL queries (57%), and a significant number of nonce and capability checks (10 each). The taint analysis also reported no critical or high severity issues with unsanitized paths, which is encouraging. However, the presence of one AJAX handler without authentication checks represents a significant attack vector that could be exploited by unauthenticated users. The plugin also bundles a very outdated version of jQuery (v1.3.2), which is a known risk for potential vulnerabilities. The vulnerability history is a major concern, with a total of 6 known CVEs, including 1 critical and 3 high severity issues. While currently unpatched, this history indicates a pattern of recurring security weaknesses, including cross-site scripting, deserialization vulnerabilities, CSRF, improper input validation, and access control flaws. This suggests that even with some good security practices in place, there are fundamental issues in the plugin's development that have led to persistent vulnerabilities.
Key Concerns
- Unprotected AJAX handler
- Bundled outdated jQuery library
- 1 critical CVE history
- 3 high CVE history
- 2 medium CVE history
- SQL queries partially not prepared
Invite Anyone Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
Invite Anyone <= 1.4.7 - Reflected Cross-Site Scripting
Invite Anyone <= 1.3.18 - PHP Object Injection
Invite Anyone < 1.3.16 - Cross-Site Request Forgery
Invite Anyone <= 1.3.15 - Improper Input Validation
Invite Anyone < 1.3.16 - Email Injection
Invite Anyone <= 1.3.14 - Change of Email Invitation Content
Invite Anyone Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Invite Anyone Attack Surface
AJAX Handlers 2
WordPress Hooks 45
Maintenance & Trust
Invite Anyone Maintenance & Trust
Maintenance Signals
Community Trust
Invite Anyone Alternatives
BP Post Status
bp-post-status
Adds BuddyPress status options for posts - Group posts (public, site members only and group only, Members Only, Followers, Following and Friends only …
Registration Options for BuddyPress
bp-registration-options
Moderate new BuddyPress members and fight BuddyPress spam.
BuddyPress Group Email Subscription
buddypress-group-email-subscription
This powerful plugin allows users to receive email notifications of group activity. Weekly or daily digests are available.
RumbleTalk Live Group Chat – HTML5
rumbletalk-chat-a-chat-with-themes
Live group chat plugin for WordPress. Integrate it into your website in minutes. Create one or multiple rooms effortlessly.
BP Group Documents
bp-group-documents
BP Group Documents creates a page within each BuddyPress group to upload and any type of file or document.
Invite Anyone Developer Profile
27 plugins · 12K total installs
How We Detect Invite Anyone
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/invite-anyone/admin/admin-css.css/wp-content/plugins/invite-anyone/admin/admin-js.js/wp-content/plugins/invite-anyone/vendor/harding-group/buddypress-120-url-polyfills/js/bp-120-url-polyfills.jsinvite-anyone/admin/admin-js.js?ver=invite-anyone/admin/admin-css.css?ver=HTML / DOM Fingerprints
bp-invite-anyonedata-invite-anyone-formdata-invite-anyone-idinvite_anyone_admin_params/wp-json/invite-anyone/v1/invite[invite_form][invite_friends][invite_anyone]