Activity Link Preview For BuddyPress
Activity Link Preview For BuddyPress turns a plain URL into a rich card. When a member pastes a link into the activity composer or a comment, the plugin reads the page, pulls a title, description and image, and shows a preview card before they post. Saved previews render server-side, so they still display when JavaScript is off. It needs BuddyPress or BuddyBoss Platform active. There is no settings page: previews work as soon as you activate the plugin, and developers can change behaviour through filters. What you get Rich previews as members type * Detects URLs as they are typed or pasted into the activity form. * Shows title, description and a featured image in a card the member can review before posting. * Multiple image selection: when a page offers several images, prev and next buttons let the member pick one, with an “Image X of Y” counter. * The preview clears itself when the URL is removed from the composer, and blocked or invalid URLs show an inline error instead of failing quietly. Internal member and group cards, with no HTTP request * Sharing a link to a member profile on your own site (/members/username/) builds a card from your database: display name, the XProfile About text, and the member’s avatar. * Sharing a link to a group (/groups/group-slug/) builds a card with the group name, description and group avatar. * Because this reads locally, there is no self-request and no external fetch, which keeps busy sites fast. Comments and embeds * Link previews work in activity comments and replies, not just top-level posts. * Native embeds for Twitter/X and Facebook. * Inline video and rich embeds via WordPress oEmbed (YouTube, Vimeo and other providers WordPress supports). * Short URLs (bit.ly, tinyurl and similar) are resolved to the real destination before the preview is built. Fast and safe by default * Per-URL caching, plus 15-minute negative caching so a slow or unreachable link is not retried on every render. * Comment rendering never fetches remote URLs, so a dead link cannot delay a page load. * SSRF protection blocks localhost, private and reserved IP ranges, and re-validates redirect targets. * Nonce verification, logged-in-only parsing, and sanitized and escaped output. Works alongside your platform * On BuddyBoss Platform with its own link preview enabled, this plugin stands down so you never get two cards on one post. * On Youzify with its wall URL preview enabled, it does the same. * Preview data is included in the BuddyPress REST API activity response. Developer friendly * bp_activity_link_preview_load_assets – control which pages load the CSS, JS and social SDKs. * bp_activity_parse_url_preview – filter the preview data returned by the parse endpoint. * bp_activity_link_parse_url – filter the parsed result before it is returned. * bp_activity_link_parse_url_shorten_url_provider – add or remove short-URL providers to resolve. * bp_oembed_discover_support – opt in to oEmbed discovery for unknown providers. * bp_activity_link_preview_enable_comments – turn preview handling in activity comments on or off. Perfect For BuddyPress and BuddyBoss communities where members share articles, videos and news Groups that use the activity stream as a reading or link-sharing feed Communities that link internally to member profiles and groups Any activity stream that currently shows bare, unclickable-looking URLs Premium Support Our support team can help with setup, theme compatibility and troubleshooting. Reach us through the links below. Documentation Documentation and Support – Setup walkthrough and usage guides for every Wbcom plugin Translations English (default) Ready for translation in your language with the included POT file RTL language support included Links Plugin Homepage Documentation Support Request Features Compatibility WordPress 6.5 and higher PHP 8.0 and higher BuddyPress 6.0+ or BuddyBoss Platform (required – the plugin deactivates itself if neither is active) Tested with popular themes including BuddyX, Reign and Youzify What’s New in 1.7.4 A performance and security pass. Plugin assets and the Twitter and Facebook SDKs now load only in activity contexts instead of on every page. Failed link lookups are cached for 15 minutes and comment rendering never fetches remote URLs, so slow links no longer hold up a page. Blocked or invalid URLs now report the problem in the composer, scraped titles and descriptions are sanitized before saving, and short-URL resolution re-validates its redirect target against the SSRF guard. Third-Party Services This plugin renders native Twitter/X and Facebook embeds. Those embeds can only be rendered by each network’s own script, so the plugin loads that script directly from the network: Twitter/X widgets.js, loaded from platform.twitter.com. Terms of service: https://twitter.com/en/tos – Privacy policy: https://twitter.com/en/privacy Facebook SDK, loaded from connect.facebook.net. Terms of service: https://www.facebook.com/terms.php – Privacy policy: https://www.facebook.com/privacy/policy/ These scripts load only on BuddyPress activity screens (the activity directory, member activity and group screens), never site-wide. On those screens they load whether or not a Twitter or Facebook link is actually present, so the visitor’s browser contacts Twitter and Facebook on every activity page view. Those services can therefore see the visitor’s IP address, user agent and referring page, and may set their own cookies. If your site needs to avoid that (for example to satisfy a consent requirement), use the bp_activity_link_preview_load_assets filter to stop the assets loading: add_filter( 'bp_activity_link_preview_load_assets', '__return_false' ); No data is sent to Wbcom Designs, and the plugin itself collects nothing. More Free Tools from Wbcom Designs Rich link previews make your activity stream worth reading, but a stream is only one part of a community. These other free tools from Wbcom Designs fill in the rest of the space your members spend time in, from the theme and social network itself to forums, media, events, gamification, directories, jobs, and courses. BuddyX – A free, fast community theme for BuddyPress, BuddyBoss and PeepSo with a modern layout and dark mode. BuddyNext – Stand up a complete WordPress community with activity streams, member spaces, profiles, direct messaging, and built-in moderation. Jetonomy – Add forums, question-and-answer boards, and idea spaces that stay tidy through trust-based auto-moderation even past 100,000 topics. Mediaverse – Let members build photo and video albums, react, follow each other, and message privately while AI moderation keeps things clean. Eventonomy – Run community events with RSVPs, calendars, and front-end submissions. WB Gamification – Reward members with points, badges, and leaderboards to keep engagement high. Listora – Publish searchable directories across ten listing types with reviews, maps, and member-submitted entries from the front end. WP Career Board – Add a job board with front-end listings, applications, and employer profiles. Learnomy – Build and sell online courses, auto-grade quizzes, collect payments, and award certificates when learners finish.
Top keywords
- activity22×1.95%
- link18×1.60%
- preview14×1.24%
- facebook9×0.80%
- member9×0.80%
- twitter9×0.80%
- load8×0.71%
- page8×0.71%
- activity link7×0.62%
- bp7×0.62%
- buddypress7×0.62%
- url7×0.62%
MH User Activity Monitor
MH User Activity Monitor shows in real time which users, visitors, WooCommerce customers and bots are currently active on your WordPress website. The plugin helps administrators identify unusual activity, cart sessions, bot traffic and suspicious requests more quickly, with privacy options such as IP anonymization, data-saving mode and automatic cleanup. Live monitoring for WordPress websites MH User Activity Monitor displays active sessions directly in the WordPress admin area. Administrators can see which visitors are currently online, whether logged-in users are active, which page types are being viewed and when the last activity occurred. The overview uses dashboard cards, filters, sorting and live refresh. This makes it easier to distinguish normal visitor activity from unusual access patterns. Administrators can also export the currently filtered session overview as a CSV file for short-term support or security review workflows. Keep an eye on WooCommerce carts When WooCommerce is active, the plugin can display active cart sessions. Depending on the selected setting, it stores and displays only the item count, item count and cart total, or detailed product information. This can help shop owners see whether customers currently have products in their cart, whether carts are abandoned or whether unusual sessions appear in the checkout area. Detect bots and suspicious requests The plugin detects known bots, crawlers, SEO tools, AI crawlers, social media preview bots and suspicious request patterns. Examples include requests to login areas, XML-RPC, .env files, .git directories or other typical scanner targets. The bot and risk indicators are not a firewall and do not replace a dedicated security plugin. They help make suspicious technical traffic more visible and easier to classify. Privacy-friendly settings Because the plugin processes technical visitor data, it includes several privacy options. New installations use anonymized IP addresses by default. Additional privacy modes such as None, Standard, Data-saving and Strict are available. Stored URLs and referrers are saved without query parameters so sensitive values such as tokens, email addresses, search terms or tracking parameters are not stored unnecessarily. User-agent, URL and referrer values are also length-limited to reduce the amount of stored data. Additional options include automatic cleanup via WordPress-Cron, ignored IP rules, CIDR support, WooCommerce cart modes and the ability to disable the frontend ping completely. Who is this plugin for? The plugin is suitable for operators of WordPress websites, WooCommerce shops, membership areas, booking sites and editorial websites who want a short-term view of what is happening on their website right now. Typical use cases include: Shop owners want to monitor active carts and checkout sessions. Administrators want to identify unusual bot traffic or scanners more quickly. Website operators want to see which pages are currently being visited. Support teams want to understand short-term technical visitor activity. Operators of smaller websites want a simple live overview without external tracking services. The plugin is intended for short-term technical monitoring. Site operators should check which data they really need, how long it is stored and whether information must be added to their privacy policy. Stability note This version is marked as the current stable build. Translations, help texts, screenshots, version metadata and basic PHP/ZIP checks were reviewed again before release. Requirements WordPress 6.2 or newer. PHP 7.4 or newer. Tested up to WordPress 7.0. WooCommerce is optional and only required for cart monitoring.