
Awebsome! Online Registered Users Widget Security & Risk Analysis
wordpress.org/plugins/awebsome-online-registered-users-widgetShows your online/offline registered users by some display options.
Is Awebsome! Online Registered Users Widget Safe to Use in 2026?
Generally Safe
Score 85/100Awebsome! Online Registered Users Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin exhibits a generally good security posture due to its lack of identified vulnerabilities in its history and its use of prepared statements for all SQL queries. The absence of an attack surface with unprotected entry points is also a positive sign. However, the static analysis reveals a significant concern: the presence of the `create_function` dangerous function, which can be exploited to execute arbitrary PHP code if used with user-supplied input. While taint analysis found no specific flows, this is likely due to the limited scope of the analysis or the absence of dynamic input being passed to this function in the analyzed code. The lack of capability checks and nonce checks, combined with the presence of a dangerous function, suggests a potential for privilege escalation or unauthorized actions if an attacker can trigger the `create_function` with malicious input. The high percentage of properly escaped output is a mitigating factor, but the single dangerous function remains a notable risk. Overall, while the plugin has strengths in its SQL handling and lack of historical vulnerabilities, the presence of `create_function` without apparent safeguards introduces a critical risk that requires immediate attention.
Key Concerns
- Presence of dangerous function `create_function`
- Missing capability checks
- Missing nonce checks
Awebsome! Online Registered Users Widget Security Vulnerabilities
Awebsome! Online Registered Users Widget Code Analysis
Dangerous Functions Found
Output Escaping
Awebsome! Online Registered Users Widget Attack Surface
WordPress Hooks 6
Maintenance & Trust
Awebsome! Online Registered Users Widget Maintenance & Trust
Maintenance Signals
Community Trust
Awebsome! Online Registered Users Widget Alternatives
WP-UserOnline
wp-useronline
Enable you to display how many users are online on your Wordpress blog with detailed statistics.
View Admin As
view-admin-as
View the WordPress admin as a different role or visitor, switch between users, temporarily change your capabilities, set screen settings for roles.
Expire Users
expire-users
Set expiry dates for user logins.
HM Multiple Roles
hm-multiple-roles
It hides the default role dropdown list and displays a list of role checkboxes to select multiple roles for a user.
WP Online Active Users
online-active-users
WP Online Active Users is a lightweight, powerful plugin to monitor and display how many users are currently online active on your WordPress website.
Awebsome! Online Registered Users Widget Developer Profile
4 plugins · 130 total installs
How We Detect Awebsome! Online Registered Users Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/awebsome-online-registered-users-widget/css/frontend.css/wp-content/plugins/awebsome-online-registered-users-widget/css/backend.cssHTML / DOM Fingerprints
aws-oruwaws-oruw-othersaws-oruw-onlysid="aws_oruw_gravatars"name="aws_oruw_gravatars"id="aws_oruw_authlinks"name="aws_oruw_authlinks"id="aws_oruw_categorize"name="aws_oruw_categorize"+14 more