LH Disable BP Registration Security & Risk Analysis

wordpress.org/plugins/lh-disable-bp-registration

Shuts down registration via the usual Buddypress method, all other functionality is not effected.

10 active installs v1.03 PHP + WP + Updated Mar 11, 2021
buddypressdisableregisterregistration
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LH Disable BP Registration Safe to Use in 2026?

Generally Safe

Score 85/100

LH Disable BP Registration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "lh-disable-bp-registration" v1.03 plugin exhibits a strong security posture based on the provided static analysis. The absence of any detected dangerous functions, SQL queries without prepared statements, unescaped output, file operations, external HTTP requests, or nonces is highly commendable and indicates careful development practices. Furthermore, the plugin has no recorded vulnerabilities, including critical or high severity ones, suggesting a history of stable and secure operation.

However, the analysis reveals a complete lack of authorization checks (capability checks) on all its entry points. While the current version doesn't expose any explicit entry points like AJAX handlers, REST API routes, or shortcodes, this lack of capability checks could become a significant concern if the plugin is extended or modified in the future. The analysis also shows no nonce checks, which are crucial for preventing CSRF attacks on any actions that might be added later.

In conclusion, the plugin is currently very secure due to its limited functionality and absence of known vulnerabilities. The development team has adhered to good coding practices regarding data handling and output. The primary weakness lies in the potential for future security issues due to the complete absence of capability checks. This is a latent risk that would only manifest if new, potentially sensitive, functionality were added without proper access controls.

Key Concerns

  • No capability checks on entry points
  • No nonce checks on potential actions
Vulnerabilities
None known

LH Disable BP Registration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LH Disable BP Registration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

LH Disable BP Registration Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterbp_get_signup_pagelh-disable-bp-registration.php:44
actionplugins_loadedlh-disable-bp-registration.php:66
Maintenance & Trust

LH Disable BP Registration Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMar 11, 2021
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

LH Disable BP Registration Developer Profile

shawfactor

77 plugins · 15K total installs

91
trust score
Avg Security Score
87/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect LH Disable BP Registration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about LH Disable BP Registration