
Simple BuddyPress Profile Privacy Security & Risk Analysis
wordpress.org/plugins/simple-buddypress-profile-privacyAllow your members to select additional privacy settings for who can view their profile and it's visibility on the directory page.
Is Simple BuddyPress Profile Privacy Safe to Use in 2026?
Generally Safe
Score 85/100Simple BuddyPress Profile Privacy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "simple-buddypress-profile-privacy" plugin v0.7.9 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL injection prevention, with all queries using prepared statements. It also shows a high percentage of properly escaped output and a single nonce check, which are positive indicators. The absence of known CVEs and a clean vulnerability history suggest a generally stable and well-maintained codebase.
However, a significant concern lies within the plugin's attack surface. The static analysis reveals one AJAX handler that lacks authentication checks. This unprotected entry point is a critical security weakness, as it could potentially be exploited by unauthenticated users to trigger unintended actions or access sensitive data. While taint analysis did not reveal any critical or high-severity flows, the presence of an unprotected AJAX handler bypasses fundamental security controls and poses a direct risk.
In conclusion, while the plugin has strengths in secure coding practices for SQL and output handling, the single unprotected AJAX handler significantly elevates its risk profile. This is the primary area that requires immediate attention to mitigate potential security vulnerabilities. The lack of past vulnerabilities is encouraging but does not negate the current risk presented by the identified unprotected entry point.
Key Concerns
- AJAX handler without auth check
Simple BuddyPress Profile Privacy Security Vulnerabilities
Simple BuddyPress Profile Privacy Code Analysis
Output Escaping
Data Flow Analysis
Simple BuddyPress Profile Privacy Attack Surface
AJAX Handlers 1
WordPress Hooks 13
Maintenance & Trust
Simple BuddyPress Profile Privacy Maintenance & Trust
Maintenance Signals
Community Trust
Simple BuddyPress Profile Privacy Alternatives
BP Simple Private
bp-simple-private
A simple Private Content settings plugin for BuddyPress or the BuddyBoss Platform.
Wbcom Designs – Private Community for BuddyPress
lock-my-bp
Create a private BuddyPress community by restricting access to non-members. Control who sees what with flexible privacy settings.
BuddyPress Activity Privacy
buddypress-activity-privacy
BuddyPress Activity Privacy plugin add a privacy level to activity stream component.
LH Private BuddyPress
lh-private-buddypress
Protect your BuddyPress Installation from strangers. Only registered users will be allowed to view directory pages, activity and profile pages.
BP MPO Activity Filter
bp-mpo-activity-filter
When using More Privacy Options, this plugin removes items from BP activity streams according to user roles.
Simple BuddyPress Profile Privacy Developer Profile
1 plugin · 200 total installs
How We Detect Simple BuddyPress Profile Privacy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-buddypress-profile-privacy/js/simple-buddypress-profile-privacy-admin.jssimple-buddypress-profile-privacy/js/simple-buddypress-profile-privacy-admin.js?ver=0.7HTML / DOM Fingerprints
bp-profile-privacy-settingsdata-privacy-settingdata-hide-directorysbpp04_get_hidden_members