Activity Link Preview For BuddyPress turns a plain URL into a rich card. When a member pastes a link into the activity composer or a comment, the plugin reads the page, pulls a title, description and image, and shows a preview card before they post. Saved previews render server-side, so they still display when JavaScript is off.
It needs BuddyPress or BuddyBoss Platform active. There is no settings page: previews work as soon as you activate the plugin, and developers can change behaviour through filters.
What you get
Rich previews as members type
- Detects URLs as they are typed or pasted into the activity form.
- Shows title, description and a featured image in a card the member can review before posting.
- Multiple image selection: when a page offers several images, prev and next buttons let the member pick one, with an "Image X of Y" counter.
-
The preview clears itself when the URL is removed from the composer, and blocked or invalid URLs show an inline error instead of failing quietly.
Internal member and group cards, with no HTTP request
-
Sharing a link to a member profile on your own site (/members/username/) builds a card from your database: display name, the XProfile About text, and the member's avatar.
- Sharing a link to a group (/groups/group-slug/) builds a card with the group name, description and group avatar.
-
Because this reads locally, there is no self-request and no external fetch, which keeps busy sites fast.
Comments and embeds
-
Link previews work in activity comments and replies, not just top-level posts.
- Native embeds for Twitter/X and Facebook.
- Inline video and rich embeds via WordPress oEmbed (YouTube, Vimeo and other providers WordPress supports).
-
Short URLs (bit.ly, tinyurl and similar) are resolved to the real destination before the preview is built.
Fast and safe by default
-
Per-URL caching, plus 15-minute negative caching so a slow or unreachable link is not retried on every render.
- Comment rendering never fetches remote URLs, so a dead link cannot delay a page load.
- SSRF protection blocks localhost, private and reserved IP ranges, and re-validates redirect targets.
-
Nonce verification, logged-in-only parsing, and sanitized and escaped output.
Works alongside your platform
-
On BuddyBoss Platform with its own link preview enabled, this plugin stands down so you never get two cards on one post.
- On Youzify with its wall URL preview enabled, it does the same.
-
Preview data is included in the BuddyPress REST API activity response.
Developer friendly
-
bp_activity_link_preview_load_assets - control which pages load the CSS, JS and social SDKs.
bp_activity_parse_url_preview - filter the preview data returned by the parse endpoint.
bp_activity_link_parse_url - filter the parsed result before it is returned.
bp_activity_link_parse_url_shorten_url_provider - add or remove short-URL providers to resolve.
bp_oembed_discover_support - opt in to oEmbed discovery for unknown providers.
bp_activity_link_preview_enable_comments - turn preview handling in activity comments on or off.
Perfect For
- BuddyPress and BuddyBoss communities where members share articles, videos and news
- Groups that use the activity stream as a reading or link-sharing feed
- Communities that link internally to member profiles and groups
- Any activity stream that currently shows bare, unclickable-looking URLs
Premium Support
Our support team can help with setup, theme compatibility and troubleshooting. Reach us through the links below.
Documentation
Translations
- English (default)
- Ready for translation in your language with the included POT file
- RTL language support included
Links
Compatibility
- WordPress 6.5 and higher
- PHP 8.0 and higher
- BuddyPress 6.0+ or BuddyBoss Platform (required - the plugin deactivates itself if neither is active)
- Tested with popular themes including BuddyX, Reign and Youzify
What's New in 1.7.4
A performance and security pass. Plugin assets and the Twitter and Facebook SDKs now load only in activity contexts instead of on every page. Failed link lookups are cached for 15 minutes and comment rendering never fetches remote URLs, so slow links no longer hold up a page. Blocked or invalid URLs now report the problem in the composer, scraped titles and descriptions are sanitized before saving, and short-URL resolution re-validates its redirect target against the SSRF guard.
Manual Installation
- Upload the
buddypress-activity-link-preview folder to /wp-content/plugins/
- Activate the plugin through the 'Plugins' menu in WordPress
- Make sure BuddyPress or BuddyBoss Platform is active
- Paste a link into an activity post and the preview appears automatically
There is no settings page. The plugin works as soon as it is activated.
Requirements
- WordPress 6.5 or higher
- PHP 8.0 or higher
- BuddyPress 6.0 or higher, or BuddyBoss Platform
1.7.5 - July 2026
Corrective release. There are no functional changes since 1.7.4.
- Fix - Restored the correct plugin files. The 1.7.4 package published on WordPress.org contained the files of a different plugin.
1.7.4 - July 2026
- New - Added German, Spanish, French, Italian and Portuguese (Brazil) translations.
- Improve - Plugin assets and the Twitter/Facebook SDKs now load only in BuddyPress activity contexts (the activity directory, member activity and group screens) instead of every page. Use the bp_activity_link_preview_load_assets filter to load them on custom pages that embed an activity stream.
- Improve - Pages with nothing to preview are remembered for 15 minutes so they are not re-fetched on every view, and comment rendering never fetches remote URLs, so slow pages no longer delay page loads. A momentary timeout or provider hiccup is no longer remembered, so a good link (a YouTube video, for example) is retried on the next view rather than showing no preview for the whole window. The window is filterable via bp_activity_link_preview_negative_cache_ttl.
- Fix - The composer preview controls (Cancel Preview, previous/next image and the image counter) were built in JavaScript with no translatable source, so they always rendered in English. They are now translatable.
- Fix - The plugin never registered its text domain, so bundled translations could never load.
- Fix - Invalid or blocked URLs now show an error message in the composer instead of failing silently.
- Fix - Preview close and image navigation icons render correctly when the admin toolbar is hidden.
- Security - Scraped link titles and descriptions are sanitized before saving and escaped on output.
- Security - Hardened short-URL resolution to resolve redirects through the WordPress HTTP API and re-validate the redirect target against the SSRF private/loopback IP guard.
1.7.3
- Code Quality: Fixed all WordPress Coding Standards (WPCS) violations
- Code Quality: Applied strict comparisons, Yoda conditions, and proper inline comment punctuation
- Code Quality: Added ABSPATH direct access protection
- Code Quality: Added missing PHPDoc parameter documentation for all functions
- Code Quality: Fixed all Plugin Check errors (0 errors)
1.7.2
- Fixed: Twitter/X and Facebook link previews now work in activity comments
- Fixed: @mentions no longer generate unwanted link previews
- Fixed: Hash symbol (#) no longer added to browser URL when closing previews
- Fixed: "Image X of undefined" no longer shows when images can't be determined
- Added: Helper function to detect social media URLs for native embed handling
- Added: Same-site URL filtering to prevent internal profile links from generating previews
- Improved: Better null checking for image navigation in JavaScript
1.7.1
- Fixed: Plugin now auto-deactivates when BuddyPress or BuddyBoss Platform is not active
- Fixed: Added proper dependency check on admin_init hook
- Improved: Better error handling for missing dependencies
1.7.0
- Fixed: Scripts now load in footer for better performance
- Fixed: Proper input sanitization with wp_unslash() for POST data
- Fixed: Use wp_parse_url() instead of parse_url() for better compatibility
- Fixed: Added translators comments for internationalization
- Fixed: Plugin Check compatibility improvements
- Fixed: Nonce verification now mandatory for security (CSRF protection)
- Fixed: BuddyPress/BuddyBoss compatibility - function_exists checks added
- Fixed: PHP 8.2+ compatibility - removed deprecated HTML-ENTITIES encoding
- Fixed: BuddyPress class name detection improved
- Fixed: Comment filter registration timing for proper enable/disable support
- Added: Plugin version constant for proper asset cache busting
- Updated: Tested up to WordPress 7.0
- Updated: Requires PHP 7.4 minimum
1.6.1
- Security: Patched SSRF (Server Side Request Forgery) vulnerability in the URL parser.
1.6.0
- Added: Filter and event hooks to extend the activity preview functionality.
- Fixed: Twitter card preview duplication issue in multiple activities.
- Fixed: Twitter preview incorrectly appended to the second activity.
- Fixed: Activity content not displaying when preview is enabled.
- Fixed: Iframe not rendering correctly in activity previews.
- Fixed: Preview not visible when sharing X (formerly Twitter) links.
- Fixed: Activity link preview index logic for accurate rendering.
- Improved: String labels and content clarity across the plugin.
- Security: Patched SSRF (Server Side Request Forgery) vulnerability in the URL parser.
- Security: Fixed XSS issues in link preview rendering to improve safety.
1.4.4
- Fix: Hide raw Facebook and Twitter URLs in BuddyPress activity content.
- Fix: Addressed multiple issues with Facebook embed functionality.
- Fix: Resolved issues with console errors during content injection.
- Enhancement: Improved code quality for better readability and maintainability.
- Update: Added support for Twitter, YouTube, and LinkedIn link previews.
- Update: Enhanced compatibility with Reddit link previews.
- Feature: Included activity link preview data in the REST API activity endpoint.
- Fix: Resolved a YouTube link preview issue.
- Fix: Addressed issues where comments and replies could not be added to activities.
1.4.3
- Fix: Issue with Reddit
- Fix: Issue with YouTube link preview
1.4.2
- Fixed: Twitter/Instagram/Facebook preview issue
1.4.0
- Fixed: Added spacing between link preview container and post button
- Fixed: Unable to comment and reply issue
1.3.0
- Fixed: Added activity link data in REST API activity endpoint
- Fixed: PHPCS Fixes
1.2.0
- Fixed: Plugin activated when BuddyPress is not activated
- Fixed: Update spacing between text and buttons
- Fixed: YouTube link issue
1.1.0
- Fixed: Legacy Support
- Fixed: Preview generation on pasting URLs
- Fixed: Error message when meta values are not readable
1.0.0