Admin User Messages Security & Risk Analysis

wordpress.org/plugins/admin-user-messages

Admin User Messages is a simple plugin that allows communication just between Admin and single users, but not a communication between user and user.

10 active installs v0.1.6 PHP + WP 3.4.1.+ Updated Aug 11, 2014
admincommunicationemailinboxmail
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Admin User Messages Safe to Use in 2026?

Generally Safe

Score 85/100

Admin User Messages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The 'admin-user-messages' plugin, in version 0.1.6, presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all its SQL queries and avoids dangerous functions, file operations, and external HTTP requests. The absence of known vulnerabilities in its history is also a strong indicator of historical diligence. However, significant concerns arise from the static analysis, particularly the complete lack of output escaping. This means that all 179 detected output points are potentially vulnerable to cross-site scripting (XSS) attacks if malicious data is injected into the system. Additionally, the absence of nonce checks across all its entry points, while not explicitly flagged as unprotected due to capability checks being present, still represents a potential weakness for certain types of attacks that could be exploited in conjunction with other vulnerabilities.

Key Concerns

  • 100% of outputs are not properly escaped
  • 0 Nonce checks on entry points
Vulnerabilities
None known

Admin User Messages Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Admin User Messages Release Timeline

v0.1.6Current
v0.1.5
v0.1.4
v0.1.3
v0.1.2
v0.1.1
v0.1
Code Analysis
Analyzed Mar 16, 2026

Admin User Messages Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
179
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

0% escaped179 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
admin_user_read_message (admin_user_messages_read_message.php:5)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Admin User Messages Attack Surface

Entry Points6
Unprotected0

Shortcodes 6

[admin_user_answer_message] admin_user_messages_answer_message.php:261
[admin_user_messages_inbox] admin_user_messages_inbox.php:262
[admin_user_read_message] admin_user_messages_read_message.php:151
[admin_user_messages_search] admin_user_messages_search.php:112
[admin_user_messages_sent_messages] admin_user_messages_sent_messages.php:249
[admin_user_messages_write_message] admin_user_messages_write_message.php:271
WordPress Hooks 3
actionwp_print_stylesadmin_user_messages.php:100
actioninitadmin_user_messages.php:105
actionadmin_menuadmin_user_messages.php:115
Maintenance & Trust

Admin User Messages Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedAug 11, 2014
PHP min version
Downloads6K

Community Trust

Rating72/100
Number of ratings5
Active installs10
Developer Profile

Admin User Messages Developer Profile

Zaunkoenig

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Admin User Messages

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/admin-user-messages/css/style.css

HTML / DOM Fingerprints

CSS Classes
aum_button
FAQ

Frequently Asked Questions about Admin User Messages