
Bulk Delete Users by Email Security & Risk Analysis
wordpress.org/plugins/bulk-delete-users-by-emailAllows bulk deletion of users by providing a list of emails. Deletes user data and meta, with batch processing for large lists.
Is Bulk Delete Users by Email Safe to Use in 2026?
Generally Safe
Score 99/100Bulk Delete Users by Email has a strong security track record. Known vulnerabilities have been patched promptly.
The "bulk-delete-users-by-email" plugin version 2.0.1 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL queries without prepared statements, unescaped output, file operations, and external HTTP requests are all positive indicators. The presence of nonce and capability checks on all identified AJAX handlers further mitigates common attack vectors like Cross-Site Request Forgery (CSRF).
However, the plugin's vulnerability history is a significant concern. With two known CVEs, including a past high-severity vulnerability, it indicates a tendency for security flaws to emerge. The types of past vulnerabilities (CSRF and Cross-Site Scripting) suggest potential issues with how user input is handled or validated, despite the static analysis currently reporting no such issues. The fact that a vulnerability was reported in late 2022 warrants attention.
In conclusion, while the current code version appears to have addressed past vulnerabilities and implements good security practices like nonce and capability checks, the historical record of significant past vulnerabilities prevents a completely clean bill of health. Users should remain vigilant and ensure the plugin is updated promptly when new versions are released to address any potential emerging threats.
Key Concerns
- Total known CVEs (2)
- Past high severity vulnerability
- Past medium severity vulnerability
Bulk Delete Users by Email Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Bulk Delete Users by Email <= 1.2 - Cross-Site Request Forgery
Bulk Delete Users by Email <= 1.2 - Reflected Cross-Site Scripting
Bulk Delete Users by Email Code Analysis
Bulk Delete Users by Email Attack Surface
AJAX Handlers 2
WordPress Hooks 2
Maintenance & Trust
Bulk Delete Users by Email Maintenance & Trust
Maintenance Signals
Community Trust
Bulk Delete Users by Email Alternatives
Delete Me
delete-me
Allow users with specific WordPress roles to delete themselves from the Your Profile page or anywhere Shortcodes can be used.
Bulk Delete Users by Keyword
bulk-delete-users-by-keyword
Efficiently manage your WordPress users with keyword-based bulk deletion capabilities.
Users Bulk Delete With Preview
users-bulk-delete-with-preview
Easily delete multiple WordPress users with the Users Bulk Delete With Preview plugin. Preview details before removal for accuracy and better control.
WP Bulk Delete
wp-bulk-delete
Delete posts, pages, comments, users, taxonomy terms and meta fields in bulk with different powerful filters and conditions.
Bulk Delete
bulk-delete
Bulk delete posts, pages, users, attachments, and meta fields based on complex bulk conditions & filters.
Bulk Delete Users by Email Developer Profile
1 plugin · 100 total installs
How We Detect Bulk Delete Users by Email
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bulk-delete-users-by-email/admin-style.css/wp-content/plugins/bulk-delete-users-by-email/admin-script.js/wp-content/plugins/bulk-delete-users-by-email/admin-script.jsbulk-delete-users-by-email/admin-style.css?ver=bulk-delete-users-by-email/admin-script.js?ver=HTML / DOM Fingerprints
bdube-wrapbdube-email-listbdube-prepare-buttonbdube-resultsbdube-results-titlebdube-user-list-previewbdube-delete-buttonbdube-cancel-button+5 moreid="bdube-email-list"id="bdube-prepare-button"id="bdube-results"id="bdube-results-title"id="bdube-user-list-preview"id="bdube-delete-button"+6 morebdube_ajax/wp-json/bulk-delete-users-by-email/v1/prepare_deletion/wp-json/bulk-delete-users-by-email/v1/process_batch_deletion