BuddyPress Addon for Newsletter Security & Risk Analysis

wordpress.org/plugins/newsletter-buddypress

Integrates the BuddyPress registration with the Newsletter subscription

40 active installs v1.0.5 PHP 5.6+ WP + Updated Unknown
buddypressnewsletterregistrationsubscription
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BuddyPress Addon for Newsletter Safe to Use in 2026?

Generally Safe

Score 100/100

BuddyPress Addon for Newsletter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin "newsletter-buddypress" v1.0.5 presents a generally positive security posture based on the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points, coupled with a lack of dangerous functions and file operations, significantly reduces the potential attack surface. Furthermore, all SQL queries utilize prepared statements, which is a strong practice against SQL injection vulnerabilities. The vulnerability history is also clear, with no known CVEs, indicating a potentially well-maintained codebase.

However, a critical concern arises from the output escaping. With 3 total outputs and 0% properly escaped, there's a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data rendered to the user interface without proper sanitization could be exploited by attackers to inject malicious scripts. The complete absence of nonce checks and capability checks on potential entry points also represents a weakness, as it leaves the plugin vulnerable to Cross-Site Request Forgery (CSRF) attacks if any of the limited entry points were to be misused. While the taint analysis shows no flows, this could be due to the limited scope of the analysis or the absence of complex data flows, and should not be taken as a guarantee of complete safety.

Key Concerns

  • Output not properly escaped
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

BuddyPress Addon for Newsletter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BuddyPress Addon for Newsletter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

0% escaped3 total outputs
Attack Surface

BuddyPress Addon for Newsletter Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actioninitbuddypress.php:55
actionadmin_menubuddypress.php:77
filternewsletter_lists_notesbuddypress.php:79
actionbp_core_signup_userbuddypress.php:82
actionbp_account_details_fieldsbuddypress.php:85
actionbp_after_profile_field_contentbuddypress.php:88
Maintenance & Trust

BuddyPress Addon for Newsletter Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedUnknown
PHP min version5.6
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

BuddyPress Addon for Newsletter Developer Profile

Stefano Lissa

14 plugins · 515K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
650 days
View full developer profile
Detection Fingerprints

How We Detect BuddyPress Addon for Newsletter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
tnp-side-menu
FAQ

Frequently Asked Questions about BuddyPress Addon for Newsletter