
BuddyPress My Friends Widgets Security & Risk Analysis
wordpress.org/plugins/my-friends-widgets-for-buddypressBuddyPress My Friends Widgets includes two widgets to display a logged in user's friends. The small size shows 40px x 40px avatars and the big si …
Is BuddyPress My Friends Widgets Safe to Use in 2026?
Generally Safe
Score 85/100BuddyPress My Friends Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "my-friends-widgets-for-buddypress" v1.0 presents a mixed security posture. On one hand, the static analysis indicates a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, there are no dangerous functions, file operations, external HTTP requests, or bundled libraries. The complete absence of known CVEs and vulnerability history is also a positive indicator. However, a significant concern arises from the output escaping. With 6 total outputs and 0% properly escaped, this indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The lack of nonce checks and capability checks across any entry points, combined with the lack of taint analysis data (which could be due to an absence of taintable code or an incomplete analysis), leaves potential for various injection attacks if any unintended input can reach these unescaped outputs.
Key Concerns
- No output escaping found
- No nonce checks
- No capability checks
BuddyPress My Friends Widgets Security Vulnerabilities
BuddyPress My Friends Widgets Code Analysis
Output Escaping
BuddyPress My Friends Widgets Attack Surface
Maintenance & Trust
BuddyPress My Friends Widgets Maintenance & Trust
Maintenance Signals
Community Trust
BuddyPress My Friends Widgets Alternatives
BuddyPress Registration Widget
buddy-registration-widget
Display BuddyPress Registration form as a Widget using this Plugin.
Buddypress Jquery Activity Stream Widget
buddypress-jquery-activity-stream-widget
Let your site viewers/users easily read the activity streams by adding a simple yet customizable widget that displays streams in an animated manner.
Buddypress Widget Pack
buddypress-widget-pack
Buddypress Widget Pack is a series of 4 widgets that you can add to your Buddypress-enabled sidebar. The four widgets are: 1)Popular Members widget 2 …
BuddyPress Last Comments Widget
bp-last-comments-widget
Shows a list of most recently added BP activity comments.
Better Messages – Live Chat, Chat Rooms, Real-Time Messaging & Private Messages
bp-better-messages
Real-time messaging and chat rooms for WordPress ecosystem: private conversations, public and private chat rooms, video & audio calls, and more.
BuddyPress My Friends Widgets Developer Profile
2 plugins · 20 total installs
How We Detect BuddyPress My Friends Widgets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
avatar-blockwidget-error