Suffusion BuddyPress Pack Security & Risk Analysis

wordpress.org/plugins/suffusion-buddypress-pack

A compatibility pack for the Suffusion WordPress theme with the BuddyPress plugin.

10 active installs v1.13 PHP + WP + Updated Dec 3, 2012
buddypresssuffusiontemplate
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Suffusion BuddyPress Pack Safe to Use in 2026?

Generally Safe

Score 85/100

Suffusion BuddyPress Pack has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "suffusion-buddypress-pack" v1.13 plugin exhibits a mixed security posture. On the positive side, it has no recorded vulnerabilities (CVEs) and the taint analysis shows no critical or high-severity flows, indicating a lack of obvious, severe code injection or path traversal issues. The plugin also shows a reasonable number of capability checks and some nonce checks, suggesting an attempt to implement WordPress security best practices.

However, significant concerns arise from the static analysis. The plugin has a single AJAX entry point that completely lacks authentication checks, presenting a direct avenue for unauthorized actions. Furthermore, the extremely low percentage of SQL queries using prepared statements (6%) and output escaping (1%) points to a high likelihood of SQL injection and Cross-Site Scripting (XSS) vulnerabilities, respectively. The presence of file operations also warrants caution, especially when combined with poor input sanitization, which the low output escaping suggests is likely.

In conclusion, while the plugin's vulnerability history is clean, the static analysis reveals substantial weaknesses. The unprotected AJAX handler is a critical flaw, and the prevalent lack of prepared statements and output escaping creates a high probability of exploitable vulnerabilities. These issues significantly outweigh the positive aspects and suggest a high risk, despite the absence of historical CVEs.

Key Concerns

  • Unprotected AJAX handler
  • Low SQL prepared statement usage
  • Very low output escaping
  • File operations without context
Vulnerabilities
None known

Suffusion BuddyPress Pack Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Suffusion BuddyPress Pack Release Timeline

v1.13Current
v1.12
v1.11
v1.10
v1.06
v1.05
v1.04
v1.03
v1.02
v1.01
v1.00
Code Analysis
Analyzed Mar 16, 2026

Suffusion BuddyPress Pack Code Analysis

Dangerous Functions
0
Raw SQL Queries
48
3 prepared
Unescaped Output
586
7 escaped
Nonce Checks
1
Capability Checks
25
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

6% prepared51 total queries

Output Escaping

1% escaped593 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

3 flows
<post-form> (template-1.2\activity\post-form.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Suffusion BuddyPress Pack Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_bpp_move_template_filessuffusion-bp-pack.php:43
WordPress Hooks 20
filterwp_dropdown_pagessuffusion-bp-pack.php:34
actionpre_update_option_page_on_frontsuffusion-bp-pack.php:35
filterpage_templatesuffusion-bp-pack.php:36
actionpre_get_postssuffusion-bp-pack.php:37
filterthe_postssuffusion-bp-pack.php:38
filterbody_classsuffusion-bp-pack.php:39
filterbp_field_css_classessuffusion-bp-pack.php:41
actioninitsuffusion-bp-pack.php:457
actionafter_setup_themesuffusion-bp-pack.php:463
actionbp_member_header_actionssuffusion-bp-pack.php:473
actionbp_member_header_actionssuffusion-bp-pack.php:478
actionbp_member_header_actionssuffusion-bp-pack.php:483
actionbp_group_header_actionssuffusion-bp-pack.php:488
actionbp_group_header_actionssuffusion-bp-pack.php:489
actionbp_directory_groups_actionssuffusion-bp-pack.php:490
actionbp_directory_blogs_actionssuffusion-bp-pack.php:495
actionadmin_menusuffusion-integration-pack.php:17
actionadmin_enqueue_scriptssuffusion-integration-pack.php:18
actionwp_enqueue_scriptssuffusion-integration-pack.php:19
actionwp_print_scriptssuffusion-integration-pack.php:20
Maintenance & Trust

Suffusion BuddyPress Pack Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedDec 3, 2012
PHP min version
Downloads26K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Suffusion BuddyPress Pack Developer Profile

Sayontan Sinha

5 plugins · 10K total installs

92
trust score
Avg Security Score
88/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Suffusion BuddyPress Pack

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/suffusion-buddypress-pack/include/css/admin.css/wp-content/plugins/suffusion-buddypress-pack/include/css/bpp.css
Version Parameters
suffusion-bppsuffusion-bpp-admin

HTML / DOM Fingerprints

CSS Classes
bp-field-wrapper
JS Globals
BP_DTheme
FAQ

Frequently Asked Questions about Suffusion BuddyPress Pack