LH Buddypress Default Email Notifications Security & Risk Analysis

wordpress.org/plugins/lh-buddypress-default-email-notifications

Allows admins to control the default email preference for users on BuddyPress based social network..

10 active installs v1.00 PHP + WP 5.0+ Updated May 22, 2021
buddypresscontroldefaultemailnotification
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LH Buddypress Default Email Notifications Safe to Use in 2026?

Generally Safe

Score 85/100

LH Buddypress Default Email Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "lh-buddypress-default-email-notifications" plugin, version 1.00, exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with exposed entry points significantly limits the potential attack surface. Furthermore, the code analysis shows no dangerous functions, external HTTP requests, or file operations, which are common vectors for exploitation. The presence of nonce and capability checks, along with the exclusive use of prepared statements for SQL queries, indicates good development practices. The taint analysis revealing zero unsanitized paths further reinforces the perception of a secure codebase. The complete lack of any recorded vulnerabilities, including CVEs of any severity, over its history suggests a mature and well-maintained plugin.

Key Concerns

  • Output escaping is not fully implemented
Vulnerabilities
None known

LH Buddypress Default Email Notifications Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LH Buddypress Default Email Notifications Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
5 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

63% escaped8 total outputs
Attack Surface

LH Buddypress Default Email Notifications Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionnetwork_admin_menulh-buddypress-default-email-notifications.php:205
actionadmin_menulh-buddypress-default-email-notifications.php:210
filterdefault_user_metadatalh-buddypress-default-email-notifications.php:215
actionbp_loadedlh-buddypress-default-email-notifications.php:237
Maintenance & Trust

LH Buddypress Default Email Notifications Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMay 22, 2021
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

LH Buddypress Default Email Notifications Developer Profile

shawfactor

77 plugins · 15K total installs

91
trust score
Avg Security Score
87/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect LH Buddypress Default Email Notifications

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about LH Buddypress Default Email Notifications