You Have a New (BuddyPress) Message Security & Risk Analysis

wordpress.org/plugins/you-have-a-new-message

Notify users about new BuddyPress messages (widget & shortcode)

80 active installs v2.1 PHP + WP 3.6+ Updated Dec 31, 2018
buddypressmessagenotificationshortcodewidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is You Have a New (BuddyPress) Message Safe to Use in 2026?

Generally Safe

Score 85/100

You Have a New (BuddyPress) Message has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "you-have-a-new-message" v2.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, external HTTP requests, file operations, and a complete reliance on prepared statements for SQL queries are commendable practices. Furthermore, the high percentage of properly escaped output indicates a good effort to prevent cross-site scripting (XSS) vulnerabilities. The lack of any recorded vulnerabilities or CVEs in its history further strengthens this positive assessment, suggesting a well-maintained and secure codebase over time.

However, the analysis does highlight some areas that warrant attention. The plugin currently lacks nonce checks and capability checks for its entry points. While the static analysis reports zero unprotected entry points, the absence of these fundamental security mechanisms means that if any new entry points are introduced or if the current shortcode is ever exposed to unauthorized access without proper checks, a security vulnerability could arise. The taint analysis showing zero flows with unsanitized paths is reassuring, but the lack of explicit checks for WordPress-specific security features like nonces and capabilities creates a potential blind spot. The plugin's strengths lie in its clean code regarding SQL and output handling, but its security would be significantly bolstered by implementing robust authorization checks.

Key Concerns

  • Missing Nonce Checks
  • Missing Capability Checks
Vulnerabilities
None known

You Have a New (BuddyPress) Message Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

You Have a New (BuddyPress) Message Release Timeline

v2.1Current
v2.0
v1.1
Code Analysis
Analyzed Apr 16, 2026

You Have a New (BuddyPress) Message Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
20 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped21 total outputs
Attack Surface

You Have a New (BuddyPress) Message Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[you-have-a-new-message] you-have-a-new-message.php:68
WordPress Hooks 2
actionplugins_loadedyou-have-a-new-message.php:14
actionwidgets_inityou-have-a-new-message.php:63
Maintenance & Trust

You Have a New (BuddyPress) Message Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedDec 31, 2018
PHP min version
Downloads12K

Community Trust

Rating100/100
Number of ratings5
Active installs80
Developer Profile

You Have a New (BuddyPress) Message Developer Profile

Markus Echterhoff

6 plugins · 220 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect You Have a New (BuddyPress) Message

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
yhanm
Shortcode Output
<a class="yhanm" href="
FAQ

Frequently Asked Questions about You Have a New (BuddyPress) Message