WP-Stateless – BuddyPress Addon Security & Risk Analysis

wordpress.org/plugins/wp-stateless-buddypress-addon

Provides compatibility between the BuddyPress and the WP-Stateless plugins.

10 active installs v0.0.2 PHP 8.0+ WP 5.0+ Updated Oct 18, 2024
buddypressbuddypress-addon-extensiongoogle-cloud-storagestatelesswp-stateless
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP-Stateless – BuddyPress Addon Safe to Use in 2026?

Generally Safe

Score 92/100

WP-Stateless – BuddyPress Addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "wp-stateless-buddypress-addon" v0.0.2 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code signals indicate robust security practices, with no dangerous functions, all SQL queries using prepared statements, and all outputs properly escaped. The lack of file operations, external HTTP requests, nonce checks, and capability checks on its limited entry points further strengthens its defensive mechanisms.

The plugin's vulnerability history is also clean, with no known CVEs, making it appear secure from known threats. The absence of any identified taint flows with unsanitized paths suggests that the plugin is not susceptible to common injection vulnerabilities. However, it's important to note that the very limited attack surface might mean that some potential security checks (like capability checks or nonce checks) were not implemented simply because there were no entry points that would typically require them. This is a strength in terms of immediate risk, but it also means the plugin has not been tested in scenarios where such checks would be crucial.

In conclusion, based on the provided data, this plugin appears to be exceptionally secure. Its strengths lie in its minimal attack surface and the absence of any security issues flagged by static analysis or historical vulnerability data. The primary weakness is the lack of demonstrable security checks on entry points, which is a consequence of having virtually no entry points in the first place, rather than an oversight. For a plugin this small and with no direct user-facing interactions, this level of security is commendable.

Vulnerabilities
None known

WP-Stateless – BuddyPress Addon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP-Stateless – BuddyPress Addon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WP-Stateless – BuddyPress Addon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionxprofile_avatar_uploadedclass-buddypress.php:26
actiongroups_avatar_uploadedclass-buddypress.php:27
filterbp_core_avatar_folder_urlclass-buddypress.php:29
filterbp_core_avatar_folder_dirclass-buddypress.php:30
filterstateless_skip_cache_bustingclass-buddypress.php:31
filtersm:sync::syncArgsclass-buddypress.php:32
filterbp_core_pre_delete_existing_avatarclass-buddypress.php:33
filterbp_attachments_pre_get_attachmentclass-buddypress.php:34
actionplugins_loadedwp-stateless-buddypress-addon.php:18
filterplugin_row_metawp-stateless-buddypress-addon.php:25
Maintenance & Trust

WP-Stateless – BuddyPress Addon Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 18, 2024
PHP min version8.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP-Stateless – BuddyPress Addon Developer Profile

UDX Usability Dynamics

15 plugins · 5K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
322 days
View full developer profile
Detection Fingerprints

How We Detect WP-Stateless – BuddyPress Addon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-stateless-buddypress-addon/vendor/wpcloud/stateless-media-core/src/Compatibilities/BuddyPress/BuddyPress.php/wp-content/plugins/wp-stateless-buddypress-addon/vendor/wpcloud/stateless-media-core/src/Compatibilities/BuddyPress/BuddyPress.php/wp-content/plugins/wp-stateless-buddypress-addon/wp-stateless-buddypress-addon.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP-Stateless – BuddyPress Addon