[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fIOdVDRWEaOODx1GILIVg27lPiQHHLTomkI4eUoZxDbM":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":27,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30,"vulnerabilities":31,"developer":32,"crawl_stats":29,"alternatives":39,"analysis":126,"fingerprints":205},"lh-buddypress-email-or-message-group-members","LH Buddypress Email or Message Group Members","1.01","shawfactor","https:\u002F\u002Fprofiles.wordpress.org\u002Fshawfactor\u002F","\u003Cp>Allows Buddypress group admins to send email and private messages to all group members from the group admin\u002Fmanage section.\u003C\u002Fp>\n\u003Cp>This plugin sends each message (PM or email) individually to each group member. And supports merge tags to personalise the message for each recipient.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Like this plugin? Please consider \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fview\u002Fplugin-reviews\u002Flh-buddypress-email-or-message-group-members\u002F\" rel=\"ugc\">leaving a 5-star review\u003C\u002Fa>.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Love this plugin or want to help the LocalHero Project? Please consider \u003Ca href=\"https:\u002F\u002Flhero.org\u002Fportfolio\u002Flh-buddypress-email-or-message-group-members\u002F\" rel=\"nofollow ugc\">making a donation\u003C\u002Fa>.\u003C\u002Fstrong>\u003C\u002Fp>\n","Allows Buddypress group Admins to send email and\u002For a private message to all group members .",10,1310,100,3,"2021-07-02T06:51:00.000Z","5.7.15","5.0","",[20,21,22,23,24],"buddypress","email","groups","mass","members","https:\u002F\u002Flhero.org\u002Fportfolio\u002Flh-buddypress-email-group-members\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flh-buddypress-email-or-message-group-members.zip",85,0,null,"2026-03-15T14:54:45.397Z",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":34,"avg_security_score":35,"avg_patch_time_days":36,"trust_score":37,"computed_at":38},77,14650,87,7,91,"2026-04-03T23:11:18.047Z",[40,58,77,93,109],{"slug":41,"name":42,"version":43,"author":44,"author_profile":45,"description":46,"short_description":47,"active_installs":11,"downloaded":48,"rating":49,"num_ratings":14,"last_updated":50,"tested_up_to":51,"requires_at_least":52,"requires_php":18,"tags":53,"homepage":55,"download_link":56,"security_score":27,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":57},"groups-members-mail","Group Members Mail Plugin","1.1","alexhal","https:\u002F\u002Fprofiles.wordpress.org\u002Falexhal\u002F","\u003Cp>Allows Buddypress group Mods to send email to all group members from group admin\u002Fmanage section.\u003Cbr \u002F>\nTo enable E-mail members for mods simply put the code given below in your bp-groups-members-mail.php file in the end from wp-admin-> plugins-> editor :\u003C\u002Fp>\n\u003Cpre>\u003Ccode>add_filter('gmm_enable_for_mods','gmm_enabled_for_mods');\nfunction gmm_enabled_for_mods(){\n    return true;\n}\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>By default this “E-Mail Members” section is available to mods and admin .\u003Cbr \u002F>\nTo change it a filter is available and you can change the access like this :\u003Cbr \u002F>\nTo restrict this option to admins only\u003Cbr \u002F>\n    add_filter(‘bp_gmm_auhority’,function(){\u003Cbr \u002F>\n        return ‘admin’;\u003Cbr \u002F>\n    });\u003C\u002Fp>\n","Allows Buddypress group Mods to send email to all group members .",2259,86,"2017-01-29T19:57:00.000Z","4.6.30","3.0.1",[20,54,22,23,24],"extension-mail","http:\u002F\u002Fwww.poolgab.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fgroups-members-mail.zip","2026-03-15T15:16:48.613Z",{"slug":59,"name":60,"version":61,"author":62,"author_profile":63,"description":64,"short_description":65,"active_installs":66,"downloaded":67,"rating":68,"num_ratings":11,"last_updated":69,"tested_up_to":70,"requires_at_least":71,"requires_php":18,"tags":72,"homepage":75,"download_link":76,"security_score":13,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":57},"shortcodes-for-buddypress","Wbcom Designs – Shortcodes & Elementor Widgets For BuddyPress","2.9.1","wbcomdesigns","https:\u002F\u002Fprofiles.wordpress.org\u002Fwbcomdesigns\u002F","\u003Cp>This plugin will add an extended feature to BuddyPress. It will use Shortcode for Listing Activity Streams, Members directory, and Groups directory on any post or page within the website.\u003C\u002Fp>\n\u003Cp>With our current update, we have added three widgets to display the activity stream, member directory, and group directory using Elementor.\u003C\u002Fp>\n\u003Cdiv class=\"embed-vimeo\" style=\"text-align: center;\">\u003Ciframe loading=\"lazy\" src=\"https:\u002F\u002Fplayer.vimeo.com\u002Fvideo\u002F554193567\" width=\"750\" height=\"422\" frameborder=\"0\" webkitallowfullscreen mozallowfullscreen allowfullscreen>\u003C\u002Fiframe>\u003C\u002Fdiv>\n\u003Ch3>THEME – WORDPRESS THEME WITH OUTSTANDING BUDDYPRESS SUPPORT\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fthemes\u002Fbuddyx\u002F\" rel=\"ugc\">FREE BuddyPress Theme: BuddyX\u003C\u002Fa> – Offers unique layouts with clean code and easy-to-customise options, giving you a whole new way to visualize BuddyPress.\u003C\u002Fli>\n\u003C\u002Ful>\n","This plugin generates shortcodes for Listing Activity Streams, Members, and Groups on any website post or page.",700,51623,92,"2025-09-22T06:44:00.000Z","6.8.5","5.0.0",[73,20,74,22,24],"activity","buddypress-shortcodes","https:\u002F\u002Fgithub.com\u002Fwbcomdesigns\u002Fshortcodes-for-buddypress","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fshortcodes-for-buddypress.2.9.1.zip",{"slug":78,"name":79,"version":80,"author":81,"author_profile":82,"description":83,"short_description":84,"active_installs":13,"downloaded":85,"rating":86,"num_ratings":36,"last_updated":87,"tested_up_to":70,"requires_at_least":88,"requires_php":18,"tags":89,"homepage":18,"download_link":92,"security_score":13,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":57},"bp-local-avatars","BP Local Avatars","3.0","shanebp","https:\u002F\u002Fprofiles.wordpress.org\u002Fshanebp\u002F","\u003Cp>BP Local Avatars is a BuddyPress plugin.\u003C\u002Fp>\n\u003Cp>Do you have members or groups on your BuddyPress site who do not have an Avatar?\u003Cbr \u002F>\nAnd you do not want to show the generic default avatar?\u003Cbr \u002F>\nOr maybe you do not want each page view to include a lot of calls to gravatar.com to load avatars?\u003C\u002Fp>\n\u003Cul>\n\u003Cli>This plugin will create a Gravatar Identicon avatar, thumb and full versions, for any user who does not already have an Avatar, and save it locally.\u003C\u002Fli>\n\u003Cli>Supports user creation, user registration, user login, and Bulk Generation for user and groups.\u003C\u002Fli>\n\u003Cli>Uses the existing BuddyPress avatar directory structure.\u003C\u002Fli>\n\u003Cli>Conforms to the defined sizes for BuddyPress thumb and full avatars.\u003C\u002Fli>\n\u003Cli>Users can still upload an avatar via their profile.\u003C\u002Fli>\n\u003Cli>Groups can still upload an avatar via Group > Manage > Photo.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Usage:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\n\u003Cp>Provides an option in wp-admin under:\u003Cbr \u002F>\nSettings -> Discussion > Default Avatar > BuddyPress Identicon (Generated and Stored Locally).\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>Select and Save. Otherwise this plugin will not do anything.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>After saving, you will see a link to ‘Bulk Generate’ avatars for all users and groups who do not have a local avatar. If a user already has their own Gravatar, it will save it locally.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>For more BuddyPress plugins, please visit \u003Ca href=\"https:\u002F\u002Fwww.philopress.com\u002F\" rel=\"nofollow ugc\">PhiloPress\u003C\u002Fa>\u003C\u002Fp>\n","A BuddyPress plugin that creates Gravatar avatars for any user or group without one, and stores them locally.",10578,82,"2025-04-19T17:32:00.000Z","4.0",[90,20,91,22,24],"avatars","gravatars","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbp-local-avatars.3.0.zip",{"slug":94,"name":95,"version":96,"author":97,"author_profile":98,"description":99,"short_description":100,"active_installs":101,"downloaded":102,"rating":103,"num_ratings":14,"last_updated":104,"tested_up_to":18,"requires_at_least":18,"requires_php":18,"tags":105,"homepage":107,"download_link":108,"security_score":27,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":57},"bp-group-management","BP Group Management","0.6","Boone Gorges","https:\u002F\u002Fprofiles.wordpress.org\u002Fboonebgorges\u002F","\u003Cp>NOTE: This plugin is not recommended for users of BuddyPress 1.7+. Instead, use BP’s Groups panel in the Dashboard.\u003C\u002Fp>\n\u003Cp>This plugin creates an admin panel at Dashboard > BuddyPress > Group Management. On this panel, site admins can manage BP group membership by banning, unbanning, promoting and demoting current members of any group, adding members to any group, and deleting groups.\u003C\u002Fp>\n\u003Ch3>Translation credits\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Italian: Luca Camellini\u003C\u002Fli>\n\u003Cli>Turkish: gk\u003C\u002Fli>\n\u003Cli>German: Tom\u003C\u002Fli>\n\u003Cli>Dutch: \u003Ca href=\"http:\u002F\u002Fwerkgroepen.net\u002Fwordpress\u002F\" rel=\"nofollow ugc\">Anja\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Romanian, \u003Ca href=\"http:\u002F\u002Fwebhostinggeeks.com\u002F\" rel=\"nofollow ugc\">Web Geek Science\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>B. Radenovich, Slovak (\u003Ca href=\"http:\u002F\u002Fwebhostingw.com\u002F\" rel=\"nofollow ugc\">Web Hosting Watch\u003C\u002Fa>)\u003C\u002Fli>\n\u003C\u002Ful>\n","Allows site administrators to manage group membership on versions of BuddyPress earlier than 1.7.",30,38297,46,"2013-04-30T00:24:00.000Z",[20,22,106,24],"manage","http:\u002F\u002Fteleogistic.net\u002Fcode\u002Fbuddypress\u002Fbp-group-management","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbp-group-management.0.6.zip",{"slug":110,"name":111,"version":112,"author":113,"author_profile":114,"description":115,"short_description":116,"active_installs":11,"downloaded":117,"rating":13,"num_ratings":118,"last_updated":119,"tested_up_to":120,"requires_at_least":121,"requires_php":18,"tags":122,"homepage":124,"download_link":125,"security_score":27,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":57},"bp-avatar-hover","Buddypress Avatar Hover","1.0","aghajoon","https:\u002F\u002Fprofiles.wordpress.org\u002Faghajoon\u002F","\u003Cp>BuddyPress  Avatar Hover let’s you add a pop box when hovering on the group\u002Fmember avatars and gives you more information at a glance.\u003Cbr \u002F>\nif you install bp-cover plugin , bp avatar hover show cover of memeber\u002Fgroup\u003C\u002Fp>\n","BuddyPress  Avatar Hover let's you add a pop box when hovering on the group\u002Fmember avatars and gives you more information at a glance.",5312,1,"2016-06-07T14:09:00.000Z","4.5.33","3.8",[73,123,20,22,24],"avatar","http:\u002F\u002Fwebcaffe.ir","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbp-avatar-hover.zip",{"attackSurface":127,"codeSignals":144,"taintFlows":170,"riskAssessment":198,"analyzedAt":204},{"hooks":128,"ajaxHandlers":140,"restRoutes":141,"shortcodes":142,"cronEvents":143,"entryPointCount":28,"unprotectedCount":28},[129,135],{"type":130,"name":131,"callback":132,"file":133,"line":134},"action","bp_init","plugin_init","lh-buddypress-email-or-message-group-members.php",272,{"type":136,"name":137,"callback":138,"file":133,"line":139},"filter","groups_create_group_steps","closure",282,[],[],[],[],{"dangerousFunctions":145,"sqlUsage":146,"outputEscaping":148,"fileOperations":28,"externalRequests":28,"nonceChecks":118,"capabilityChecks":28,"bundledLibraries":169},[],{"prepared":28,"raw":28,"locations":147},[],{"escaped":149,"rawEcho":11,"locations":150},2,[151,155,157,159,161,162,164,165,166,168],{"file":152,"line":153,"context":154},"classes\\lh_begm-screen-class.php",37,"raw output",{"file":152,"line":156,"context":154},38,{"file":152,"line":158,"context":154},39,{"file":152,"line":160,"context":154},43,{"file":152,"line":160,"context":154},{"file":152,"line":163,"context":154},44,{"file":152,"line":163,"context":154},{"file":152,"line":163,"context":154},{"file":152,"line":167,"context":154},45,{"file":152,"line":167,"context":154},[],[171,190],{"entryPoint":172,"graph":173,"unsanitizedCount":28,"severity":189},"settings_screen_save (classes\\lh_begm-screen-class.php:54)",{"nodes":174,"edges":186},[175,180],{"id":176,"type":177,"label":178,"file":152,"line":179},"n0","source","$_POST (x2)",71,{"id":181,"type":182,"label":183,"file":152,"line":184,"wp_function":185},"n1","sink","update_option() [Settings Manipulation]",149,"update_option",[187],{"from":176,"to":181,"sanitized":188},true,"low",{"entryPoint":191,"graph":192,"unsanitizedCount":28,"severity":189},"\u003Clh_begm-screen-class> (classes\\lh_begm-screen-class.php:0)",{"nodes":193,"edges":196},[194,195],{"id":176,"type":177,"label":178,"file":152,"line":179},{"id":181,"type":182,"label":183,"file":152,"line":184,"wp_function":185},[197],{"from":176,"to":181,"sanitized":188},{"summary":199,"deductions":200},"The \"lh-buddypress-email-or-message-group-members\" plugin v1.01 demonstrates a generally strong security posture based on the provided static analysis.  The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface, and critically, all identified SQL queries utilize prepared statements. The plugin also correctly implements a nonce check, which is a fundamental security control.  However, a significant concern arises from the low percentage of properly escaped output (17%). This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied or dynamically generated content could be rendered without proper sanitization, allowing attackers to inject malicious scripts.  The plugin has no recorded vulnerability history, which is a positive indicator, but this should be viewed in conjunction with the identified output escaping issues. Overall, while the plugin avoids common pitfalls like raw SQL and a broad attack surface, the unescaped output presents a clear and present danger that needs immediate attention.",[201],{"reason":202,"points":203},"Insufficient output escaping",8,"2026-03-16T23:33:49.064Z",{"wat":206,"direct":214},{"assetPaths":207,"generatorPatterns":209,"scriptPaths":210,"versionParams":211},[208],"\u002Fwp-content\u002Fplugins\u002Flh-buddypress-email-or-message-group-members\u002Fjs\u002Flh_begm-screen-script.js",[],[208],[212,213],"lh-buddypress-email-or-message-group-members\u002Fstyle.css?ver=","lh_begm-screen-script.js?ver=",{"cssClasses":215,"htmlComments":217,"htmlAttributes":221,"restEndpoints":227,"jsGlobals":228,"shortcodeOutput":230},[216],"lh-begm-screen-message",[218,219,220],"\u003C!-- A simple WordPress plugin to send mails to all buddypress group members -->","\u003C!-- Changes the text of the Submit button -->","\u003C!-- on the Edit page -->",[222,223,224,225,226],"name=\"lh_begm_recipient_email\"","name=\"lh_begm_recipient_name\"","name=\"lh_begm_subject\"","name=\"lh_begm_message\"","name=\"lh_begm_message_type\"",[],[229],"LH_BEGM_SCREEN_SETTINGS",[]]