
Advanced User Agent Displayer Security & Risk Analysis
wordpress.org/plugins/advanced-user-agent-displayerThis wordpress plugin adds user agent information to your blog comments by adding browser and platform icons and lets visitors know the user agent of …
Is Advanced User Agent Displayer Safe to Use in 2026?
Generally Safe
Score 85/100Advanced User Agent Displayer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "advanced-user-agent-displayer" v2.7.5.2 plugin exhibits a generally good security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, all SQL queries are prepared, and there are no dangerous functions, file operations, or external HTTP requests. However, a critical concern arises from the output escaping. With 100% of outputs not being properly escaped, there is a high risk of cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user's browser. The taint analysis also indicates two flows with unsanitized paths, which, while not classified as critical or high severity in this specific analysis, suggest potential injection risks that could be exacerbated by the lack of output escaping.
The vulnerability history is a strong point, with no known CVEs recorded for this plugin. This suggests a history of responsible development and maintenance, with security issues either being absent or promptly addressed. While the lack of historical vulnerabilities is positive, it should not overshadow the immediate risks identified in the code analysis. The primary weakness lies in the output handling, which could be exploited if malicious data reaches the plugin's output points. Therefore, the plugin has strengths in its limited attack surface and clean vulnerability history, but a significant weakness in its output escaping practices.
Key Concerns
- All outputs are unescaped, indicating XSS risk
- Taint analysis shows unsanitized paths
Advanced User Agent Displayer Security Vulnerabilities
Advanced User Agent Displayer Code Analysis
Output Escaping
Data Flow Analysis
Advanced User Agent Displayer Attack Surface
WordPress Hooks 5
Maintenance & Trust
Advanced User Agent Displayer Maintenance & Trust
Maintenance Signals
Community Trust
Advanced User Agent Displayer Alternatives
FL3R User Agent Comments
fl3r-user-agent-comments
Show the browser and the operating system of your users in the comments and create a chain of comments most beautiful and interesting to read!
Comments Form Star Rating Plugin for WordPress
comments-form-star-rating
Allow your customers to add star rattings in comment form.
IP Ban
simple-ip-ban
Simple IP Ban is a lightweight ip / user agent ban plugin.
User Last Login
user-last-login
Displays login datetime in manage users screen and sorts users by last login time.
CIO Custom Fields Importer
custom-fields-csv-xml-importer
Simple, easy, fast and flexible, this add-on to WP All Import processes large data sets from any XML or CSV files to any contents.
Advanced User Agent Displayer Developer Profile
6 plugins · 90 total installs
How We Detect Advanced User Agent Displayer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-user-agent-displayer/img/24/os/unknown.pngHTML / DOM Fingerprints
name="post_icon_size"name="post_show_browser"name="post_show_platform"name="general_show_unknown"name="post_location"name="show_in_dashboard"+1 more