
Wbcom Designs – Private Community for BuddyPress Security & Risk Analysis
wordpress.org/plugins/lock-my-bpCreate a private BuddyPress community by restricting access to non-members. Control who sees what with flexible privacy settings.
Is Wbcom Designs – Private Community for BuddyPress Safe to Use in 2026?
Generally Safe
Score 98/100Wbcom Designs – Private Community for BuddyPress has a strong security track record. Known vulnerabilities have been patched promptly.
The lock-my-bp v2.1.2 plugin exhibits a mixed security posture. While it demonstrates good practices by avoiding dangerous functions, file operations, and external HTTP requests, and by using prepared statements for a majority of its SQL queries, significant concerns remain regarding its attack surface. The presence of four unprotected AJAX handlers represents a considerable risk, as these are direct entry points that lack necessary authentication and authorization checks, potentially allowing unauthorized users to trigger plugin functionalities. The plugin's history of two medium-severity vulnerabilities, both related to missing authorization, further amplifies this concern and suggests a pattern of overlooking proper access control in its development. Although there are no currently unpatched CVEs and a decent percentage of output is properly escaped, the lack of robust authorization on critical entry points is a fundamental security flaw that needs immediate attention.
Key Concerns
- Unprotected AJAX handlers
- History of missing authorization vulnerabilities
- Medium severity vulnerabilities in history
Wbcom Designs – Private Community for BuddyPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Wbcom Designs <= 2.1.1 - Missing Authorization
Wbcom Designs Plugins (Various Versions) - Arbitrary Plugin Installation, Activation and Deactivation
Wbcom Designs – Private Community for BuddyPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Wbcom Designs – Private Community for BuddyPress Attack Surface
AJAX Handlers 5
Shortcodes 2
WordPress Hooks 23
Maintenance & Trust
Wbcom Designs – Private Community for BuddyPress Maintenance & Trust
Maintenance Signals
Community Trust
Wbcom Designs – Private Community for BuddyPress Alternatives
BP Simple Private
bp-simple-private
A simple Private Content settings plugin for BuddyPress or the BuddyBoss Platform.
LH Private BuddyPress
lh-private-buddypress
Protect your BuddyPress Installation from strangers. Only registered users will be allowed to view directory pages, activity and profile pages.
BP Custom Functionalities
bp-custom-functionalities
BP Custom Functionalities provides custom functionalities that regular BuddyPress users requires.
Force Login
wp-force-login
Force Login is a simple lightweight plugin that requires visitors to log in to interact with the website.
My Private Site
jonradio-private-site
Make your WordPress site private with one click for family, projects, or teams. Protection for content, login, and registration.
Wbcom Designs – Private Community for BuddyPress Developer Profile
19 plugins · 10K total installs
How We Detect Wbcom Designs – Private Community for BuddyPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lock-my-bp/admin/css/bootstrap.min.css/wp-content/plugins/lock-my-bp/admin/css/fontawesome.min.css/wp-content/plugins/lock-my-bp/admin/css/style.css/wp-content/plugins/lock-my-bp/admin/js/bootstrap.min.js/wp-content/plugins/lock-my-bp/admin/js/custom.js/wp-content/plugins/lock-my-bp/admin/js/jquery.min.js/wp-content/plugins/lock-my-bp/admin/js/sweetalert.min.js/wp-content/plugins/lock-my-bp/assets/css/lock-my-bp.css+1 more/wp-content/plugins/lock-my-bp/admin/js/bootstrap.min.js/wp-content/plugins/lock-my-bp/admin/js/custom.js/wp-content/plugins/lock-my-bp/admin/js/jquery.min.js/wp-content/plugins/lock-my-bp/admin/js/sweetalert.min.js/wp-content/plugins/lock-my-bp/assets/js/lock-my-bp.jslock-my-bp/admin/css/style.css?ver=lock-my-bp/admin/js/custom.js?ver=lock-my-bp/assets/css/lock-my-bp.css?ver=lock-my-bp/assets/js/lock-my-bp.js?ver=HTML / DOM Fingerprints
bp-lock-content-wrapbp-lock-admin-pagebp-lock-main-sectionbp-lock-settings-sectionbp-lock-section-titlebp-lock-form-groupbp-lock-input-fieldbp-lock-toggle-switch+2 more<!-- Wbcom Designs - Private Community for BuddyPress --><!-- Plugin Name: Wbcom Designs - Private Community for BuddyPress --><!-- Plugin URI: http://www.wbcomdesigns.com --><!-- Description: BuddyPress Private Community allows the site owner to lock the different BuddyPress components on the site for non-logged-in users. It also gives options to lockdown pages. -->+19 moredata-bp-lock-iddata-bp-lock-typebp_lock_ajax_object