LH Buddypress Multi Network Security & Risk Analysis

wordpress.org/plugins/lh-buddypress-multi-network

Segregate your multsite into multiple buddypress social networks.

10 active installs v1.01 PHP + WP 5.0+ Updated Mar 26, 2021
buddypressmultiplemultisitenetworksaas
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LH Buddypress Multi Network Safe to Use in 2026?

Generally Safe

Score 85/100

LH Buddypress Multi Network has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "lh-buddypress-multi-network" plugin version 1.01 exhibits a generally positive security posture based on the static analysis. The absence of dangerous functions, file operations, external HTTP requests, and the proper use of prepared statements for SQL queries are all good security practices. Furthermore, the plugin has no recorded vulnerabilities or CVEs, suggesting a history of secure development. However, there are notable areas of concern. The complete lack of nonce checks and capability checks across all identified entry points is a significant weakness. While the current attack surface is minimal and appears to have no direct unprotected entry points, the absence of these fundamental security mechanisms leaves the plugin vulnerable to potential CSRF and privilege escalation attacks should any new entry points be introduced or if existing ones are misused. The 50% rate of unescaped output also presents a risk of cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is involved in the unescaped outputs.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Half of outputs are unescaped
Vulnerabilities
None known

LH Buddypress Multi Network Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LH Buddypress Multi Network Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
1
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

50% escaped2 total outputs
Attack Surface

LH Buddypress Multi Network Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
filterbp_core_get_table_prefixlh-buddypress-multi-network.php:406
filterbp_get_user_meta_keylh-buddypress-multi-network.php:409
filterpre_update_site_option_bp-db-versionlh-buddypress-multi-network.php:412
filtersite_option_bp-db-versionlh-buddypress-multi-network.php:415
actionbp_pre_user_querylh-buddypress-multi-network.php:418
filterbp_core_get_active_member_countlh-buddypress-multi-network.php:419
actiontemplate_redirectlh-buddypress-multi-network.php:425
actionuser_registerlh-buddypress-multi-network.php:428
actionpersonal_options_updatelh-buddypress-multi-network.php:429
actionedit_user_profile_updatelh-buddypress-multi-network.php:430
actionbp_includelh-buddypress-multi-network.php:492

Scheduled Events 1

lh_bmnf_process
Maintenance & Trust

LH Buddypress Multi Network Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedMar 26, 2021
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

LH Buddypress Multi Network Developer Profile

shawfactor

77 plugins · 15K total installs

91
trust score
Avg Security Score
87/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect LH Buddypress Multi Network

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about LH Buddypress Multi Network