YD BuddyPress Feed Syndication Security & Risk Analysis

wordpress.org/plugins/yd-buddypress-feed-syndication

Syndicate RSS feeds into your user or group Activity stream

10 active installs v2.1.0 PHP + WP 2.8+ Updated Sep 6, 2011
aggregationbuddypressfeedrsssyndication
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is YD BuddyPress Feed Syndication Safe to Use in 2026?

Generally Safe

Score 85/100

YD BuddyPress Feed Syndication has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The "yd-buddypress-feed-syndication" v2.1.0 plugin exhibits a generally positive security posture based on the static analysis. The absence of direct attack surface entry points like AJAX handlers, REST API routes, and shortcodes, combined with the use of prepared statements for all SQL queries, indicates a thoughtful approach to security. Furthermore, the presence of nonce and capability checks, along with no file operations or external HTTP requests, are all strong indicators of secure coding practices.

However, a notable concern arises from the "Taint Analysis" results, which identified one flow with an unsanitized path. While no critical or high severity vulnerabilities were found in this flow, the mere presence of an unsanitized path represents a potential risk that could be exploited if the data flow is directly user-controlled. The low percentage of properly escaped output (9%) is also a significant weakness, as it suggests a widespread risk of Cross-Site Scripting (XSS) vulnerabilities across the plugin's output, even though no specific XSS vulnerabilities were flagged directly in this analysis. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign, but it does not mitigate the risks identified in the static analysis.

In conclusion, while the plugin has several strong security features and a clean vulnerability history, the identified unsanitized path and the low rate of output escaping present tangible risks that require attention. Addressing these specific areas would significantly improve the plugin's overall security.

Key Concerns

  • Flow with unsanitized path
  • Low percentage of properly escaped output
Vulnerabilities
None known

YD BuddyPress Feed Syndication Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

YD BuddyPress Feed Syndication Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
71
7 escaped
Nonce Checks
7
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

9% escaped78 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
form_footer (inc\yd-widget-framework.inc.php:642)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

YD BuddyPress Feed Syndication Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionadmin_menuinc\yd-widget-framework.inc.php:99
filterplugin_action_linksinc\yd-widget-framework.inc.php:101
filterplugin_row_metainc\yd-widget-framework.inc.php:102
actionadmin_menuinc\yd-widget-framework.inc.php:105
actionwidgets_initinc\yd-widget-framework.inc.php:107
actionwp_print_stylesinc\yd-widget-framework.inc.php:109
actionplugins_loadedinc\yd-widget-framework.inc.php:110
actionadmin_noticesinc\yd-widget-framework.inc.php:111
actionwp_footerinc\yd-widget-framework.inc.php:113
actionadmin_noticesinc\yd-widget-framework.inc.php:337
actionbp_includeinc\ydbfs.inc.php:19
filterwp_feed_cache_transient_lifetimeinc\ydbfs.inc.php:20
filterbp_get_activity_actioninc\ydbfs.inc.php:26
actioninitinc\ydbfs.inc.php:30
actionbp_template_titleinc\ydbfs.inc.php:127
actionbp_template_contentinc\ydbfs.inc.php:128

Scheduled Events 2

yd_hourly_event
yd_daily_event
Maintenance & Trust

YD BuddyPress Feed Syndication Maintenance & Trust

Maintenance Signals

WordPress version tested3.2.1
Last updatedSep 6, 2011
PHP min version
Downloads10K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Developer Profile

YD BuddyPress Feed Syndication Developer Profile

Yann at WP&Co

14 plugins · 180 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect YD BuddyPress Feed Syndication

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yd-buddypress-feed-syndication/css/yd.css
Version Parameters
yd-buddypress-feed-syndication/css/yd.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about YD BuddyPress Feed Syndication