Advanced User Access Manager Security & Risk Analysis

wordpress.org/plugins/advanced-user-access-manager

Introducing Advanced User Access Manager for WordPress – your go-to solution for precise user control. Easily restrict page access, customize login re …

0 active installs v1.0.2 PHP 7.2+ WP 6.4+ Updated Nov 17, 2024
advance-login-formlogin-redirect-login-page-customizepage-redirectpage-restriction
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Advanced User Access Manager Safe to Use in 2026?

Generally Safe

Score 92/100

Advanced User Access Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "advanced-user-access-manager" plugin v1.0.2 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, file operations, or external HTTP requests is commendable. Furthermore, all output is properly escaped, and taint analysis reveals no critical or high severity issues. The plugin also has a clean vulnerability history, with no recorded CVEs, which suggests a commitment to secure coding practices.

However, the analysis does highlight a significant area of concern: the use of raw SQL queries without prepared statements. While there is only one such query, this practice represents a potential entry point for SQL injection vulnerabilities, especially if the input used in the query is not meticulously sanitized on the server-side. The lack of capability checks on any entry points is also a weakness, as it means that all users, regardless of their role or permissions, could potentially interact with any functionality exposed by the plugin, increasing the attack surface.

In conclusion, the plugin is generally well-secured with excellent output sanitization and no known historical vulnerabilities. The primary weaknesses lie in the potential for SQL injection due to the unparameterized query and the lack of capability checks, which could allow unauthorized access to plugin features. Addressing these specific issues would significantly strengthen its security.

Key Concerns

  • Raw SQL query without prepared statement
  • No capability checks on entry points
Vulnerabilities
None known

Advanced User Access Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Advanced User Access Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
0
86 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

100% escaped86 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<settings> (includes\settings\settings.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Advanced User Access Manager Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actioninitadvanced-user-access-manager.php:109
filterlogin_headerurlincludes\Classes\class-admin-login-form-customize.php:43
filterlogin_headertextincludes\Classes\class-admin-login-form-customize.php:44
filterlogin_body_classincludes\Classes\class-admin-login-form-customize.php:45
actionadmin_menuincludes\Classes\class-admin-menu.php:43
actionlogin_redirectincludes\Classes\class-login-form-redirect.php:43
actionwp_logoutincludes\Classes\class-login-form-redirect.php:44
actiontemplate_redirectincludes\Classes\class-page-restricted.php:43
filterthe_contentincludes\Classes\class-page-restricted.php:44
actionlogin_enqueue_scriptsincludes\Classes\class-scripts-style.php:43
actionadmin_enqueue_scriptsincludes\Classes\class-scripts-style.php:44
actionwp_enqueue_scriptsincludes\Classes\class-scripts-style.php:45
filterbody_classincludes\functions.php:179
actionlogin_enqueue_scriptsincludes\login-inline-css.php:106
Maintenance & Trust

Advanced User Access Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedNov 17, 2024
PHP min version7.2
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Advanced User Access Manager Developer Profile

WPFound

5 plugins · 110 total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Advanced User Access Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-user-access-manager/assets/css/default.css/wp-content/plugins/advanced-user-access-manager/assets/css/login-page.css/wp-content/plugins/advanced-user-access-manager/assets/admin/css/admin.css/wp-content/plugins/advanced-user-access-manager/assets/admin/js/admin.js/wp-content/plugins/advanced-user-access-manager/assets/admin/js/tabs.js/wp-content/plugins/advanced-user-access-manager/assets/admin/js/color-picker.js
Script Paths
/wp-content/plugins/advanced-user-access-manager/assets/admin/js/admin.js/wp-content/plugins/advanced-user-access-manager/assets/admin/js/tabs.js/wp-content/plugins/advanced-user-access-manager/assets/admin/js/color-picker.js
Version Parameters
advanced-user-access-manager/assets/css/default.css?ver=advanced-user-access-manager/assets/css/login-page.css?ver=advanced-user-access-manager/assets/admin/css/admin.css?ver=advanced-user-access-manager/assets/admin/js/admin.js?ver=advanced-user-access-manager/assets/admin/js/tabs.js?ver=advanced-user-access-manager/assets/admin/js/color-picker.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Advanced User Access Manager