
Admin User Messages Security & Risk Analysis
wordpress.org/plugins/admin-user-messagesAdmin User Messages is a simple plugin that allows communication just between Admin and single users, but not a communication between user and user.
Is Admin User Messages Safe to Use in 2026?
Generally Safe
Score 85/100Admin User Messages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'admin-user-messages' plugin, in version 0.1.6, presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all its SQL queries and avoids dangerous functions, file operations, and external HTTP requests. The absence of known vulnerabilities in its history is also a strong indicator of historical diligence. However, significant concerns arise from the static analysis, particularly the complete lack of output escaping. This means that all 179 detected output points are potentially vulnerable to cross-site scripting (XSS) attacks if malicious data is injected into the system. Additionally, the absence of nonce checks across all its entry points, while not explicitly flagged as unprotected due to capability checks being present, still represents a potential weakness for certain types of attacks that could be exploited in conjunction with other vulnerabilities.
Key Concerns
- 100% of outputs are not properly escaped
- 0 Nonce checks on entry points
Admin User Messages Security Vulnerabilities
Admin User Messages Release Timeline
Admin User Messages Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Admin User Messages Attack Surface
Shortcodes 6
WordPress Hooks 3
Maintenance & Trust
Admin User Messages Maintenance & Trust
Maintenance Signals
Community Trust
Admin User Messages Alternatives
Change Admin Email
change-admin-email-setting-without-outbound-email
Change the WordPress admin email without requiring email confirmation - perfect for development and testing environments.
SMTP2GO for WordPress – Email Made Easy
smtp2go
Resolve email delivery issues, increase inbox placement, track sent email, get 24/7 support, and real-time reporting.
Disable New User Notification Emails
disable-new-user-notifications
This plugin does one thing - disables user registration notification emails.
Make Disable Admin Email Verification Prompt| Aims Infosoft
make-disable-admin-email-verification-prompt
Disable Admin Email Verification Prompt with checkbox option in Genearl in Settings.if you want to disable prompt then tick the chekckbox.
Disable User Password Reset Admin Notifications
disable-user-password-reset-emails
Disable admin email notifications when a user changes their password.
Admin User Messages Developer Profile
1 plugin · 10 total installs
How We Detect Admin User Messages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/admin-user-messages/css/style.cssHTML / DOM Fingerprints
aum_button