LH Buddypress Woo Security & Risk Analysis

wordpress.org/plugins/lh-buddypress-woo

Move WooCommerce My Account area to BuddyPress profile

10 active installs v1.00 PHP + WP + Updated Aug 4, 2022
buddypressecommercemy-accountshopwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is LH Buddypress Woo Safe to Use in 2026?

Generally Safe

Score 85/100

LH Buddypress Woo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "lh-buddypress-woo" v1.00 plugin exhibits an exceptionally strong security posture. The code analysis reveals no dangerous functions, no unsanitized taint flows, and all SQL queries are properly prepared. Furthermore, output escaping is 100% compliant, and there are no file operations or external HTTP requests, minimizing potential attack vectors. The complete absence of vulnerabilities in its history, including no recorded CVEs, suggests a development team that prioritizes security and has likely implemented robust security practices.

While the current analysis shows no immediate risks, the complete lack of any entry points like AJAX handlers, REST API routes, shortcodes, or cron events is unusual. This could indicate a very simple plugin or one that relies entirely on integration with other components. The absence of nonce checks and capability checks is noted, but given the lack of exploitable entry points and no recorded history of issues, these omissions do not represent a current security risk.

In conclusion, the plugin appears to be very secure at version 1.00. Its strengths lie in its clean code, secure handling of data, and an unblemished vulnerability record. The primary weakness, if it can be called that, is the lack of observable entry points, which makes a comprehensive assessment of its full attack surface challenging without understanding its integration points. However, based on the provided data, this plugin does not present any evident security concerns.

Vulnerabilities
None known

LH Buddypress Woo Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LH Buddypress Woo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries
Attack Surface

LH Buddypress Woo Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
filterwoocommerce_is_account_pagelh-buddypress-woo.php:277
actionbp_template_contentlh-buddypress-woo.php:280
actionpost_updatedlh-buddypress-woo.php:389
actiondelete_postlh-buddypress-woo.php:390
actiontrashed_postlh-buddypress-woo.php:391
actionbp_parse_querylh-buddypress-woo.php:533
filterwoocommerce_customer_edit_account_urllh-buddypress-woo.php:536
filterwoocommerce_get_endpoint_urllh-buddypress-woo.php:539
actiontemplate_redirectlh-buddypress-woo.php:542
filterlh_bp_cpp_a_get_applicable_publish_post_types_filterlh-buddypress-woo.php:548
filterlh_bp_cpp_a_get_applicable_update_post_types_filterlh-buddypress-woo.php:549
actioninitlh-buddypress-woo.php:554
actionbp_register_activity_actionslh-buddypress-woo.php:558
actionwoocommerce_checkout_order_processedlh-buddypress-woo.php:561
actionwp_insert_commentlh-buddypress-woo.php:564
actionbp_includelh-buddypress-woo.php:589
Maintenance & Trust

LH Buddypress Woo Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedAug 4, 2022
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

LH Buddypress Woo Developer Profile

shawfactor

77 plugins · 15K total installs

91
trust score
Avg Security Score
87/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect LH Buddypress Woo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lh-buddypress-woo/lh-buddypress-woo.php
Version Parameters
/lh-buddypress-woo/lh-buddypress-woo.php?ver=

HTML / DOM Fingerprints

CSS Classes
account-accountaccount-viewaccount-add-payment-methodaccount-members-area
Data Attributes
item_css_id="account"item_css_id="account-view"item_css_id="account-add-payment-method"item_css_id="account-members-area"
FAQ

Frequently Asked Questions about LH Buddypress Woo