
CBX User Online & Last Login Security & Risk Analysis
wordpress.org/plugins/cbxuseronlineShows online users based on cookie for guest and session for registered user. It also records the last login of user.
Is CBX User Online & Last Login Safe to Use in 2026?
Generally Safe
Score 100/100CBX User Online & Last Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The cbxuseronline plugin version 1.3.5 presents a mixed security posture. While it demonstrates good practices by largely avoiding dangerous functions, file operations, and external HTTP requests, and shows a respectable percentage of properly escaped outputs and prepared SQL statements, there are significant areas of concern. The plugin has a notable attack surface, with 3 out of 4 entry points lacking authentication checks. The taint analysis reveals 2 critical severity flows with unsanitized paths, indicating potential for serious vulnerabilities like remote code execution or data compromise if these flows are exploitable. The absence of any recorded vulnerabilities in its history could suggest a lack of past targeting or successful mitigation, but it does not negate the risks identified in the static analysis. Overall, the plugin has strengths in code hygiene but weaknesses in access control and data sanitization at critical entry points.
The primary risks stem from the unprotected AJAX handlers and the identified taint flows. The fact that these flows are flagged as high severity and involve unsanitized paths means an attacker could potentially leverage them to execute arbitrary code or access sensitive data. The presence of unprotected AJAX endpoints further exacerbates this risk by allowing unauthenticated access to plugin functionalities, which could then be combined with the identified taint issues. While the plugin does implement nonce and capability checks on some entry points, the unprotected ones represent a significant oversight.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows with unsanitized paths
- Large attack surface without auth
CBX User Online & Last Login Security Vulnerabilities
CBX User Online & Last Login Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
CBX User Online & Last Login Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 29
Maintenance & Trust
CBX User Online & Last Login Maintenance & Trust
Maintenance Signals
Community Trust
CBX User Online & Last Login Alternatives
WP Notification Bell
wp-notification-bell
On-site bell notifications. Display notifications custom or triggered (new posts/cpts, WooCommerce order updates, new comment replies, bbPress...)
bbPress Login Register Links On Forum Topic Pages
bbpress-login-register-links-on-forum-topic-pages
Add bbPress only sidebar, Add bbpress login link, bbpress register link, forget password link, log out link in bbpress forum index pages or bbpress si …
bbPress forum utility pack
bbp-jp-utility
This is a utility plugin that nifty to support the management of bbpress. However, some features are the Japanese version only.
bbPress Messages
bbp-messages
bbPress Messages - Simple yet powerful private messaging system tailored for bbPress.
bbPress2 BBCode
bbpress-bbcode
This plugin adds support for popular bbcode forum code to posts, comments, pages, bbpress 2.0 forums and buddypress activity and group forums.
CBX User Online & Last Login Developer Profile
9 plugins · 3K total installs
How We Detect CBX User Online & Last Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cbxuseronline/css/style.css/wp-content/plugins/cbxuseronline/js/cbxuseronline.js/wp-content/plugins/cbxuseronline/js/cbxuseronline.admin.js/wp-content/plugins/cbxuseronline/widgets/classic-widget/cbxonline-widget.css/wp-content/plugins/cbxuseronline/widgets/classic-widget/cbxonline-widget.js/wp-content/plugins/cbxuseronline/js/cbxuseronline.js/wp-content/plugins/cbxuseronline/js/cbxuseronline.admin.js/wp-content/plugins/cbxuseronline/widgets/classic-widget/cbxonline-widget.jscbxuseronline/css/style.css?ver=cbxuseronline/js/cbxuseronline.js?ver=cbxuseronline/js/cbxuseronline.admin.js?ver=cbxuseronline/widgets/classic-widget/cbxonline-widget.css?ver=cbxuseronline/widgets/classic-widget/cbxonline-widget.js?ver=HTML / DOM Fingerprints
cbxuseronline_widget_userscbxuseronline_widget_users_onlinecbxuseronline_widget_users_totalcbxuseronline_widget_users_avatarcbxuseronline_widget_user_infocbxuseronline_widget_user_namecbxuseronline_widget_user_last_login<!-- CBX User Online Widget -->data-cbxuseronline-widgetcbxuseronline_datacbxuseronline_ajax_object