
CellarWeb User Profile Access Control Security & Risk Analysis
wordpress.org/plugins/cellarweb-user-profile-access-controlAllows you to prevent individual users from editing/changing their user profile. User profile edit/change is allowed (and can't be blocked) for r …
Is CellarWeb User Profile Access Control Safe to Use in 2026?
Generally Safe
Score 100/100CellarWeb User Profile Access Control has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of 'cellarweb-user-profile-access-control' v1.01 reveals a plugin with a minimal attack surface and good internal security practices. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits potential entry points for attackers. Furthermore, all SQL queries utilize prepared statements, mitigating SQL injection risks. The plugin also demonstrates some level of capability checks within its code. However, a significant concern arises from the low percentage of properly escaped output. With only 22% of identified outputs being properly escaped, there is a substantial risk of cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user interface.
The vulnerability history for this plugin is currently clean, with no recorded CVEs. This absence of past vulnerabilities, combined with the good internal practices observed in the code, suggests a generally well-maintained plugin. However, the low output escaping rate remains a critical weakness that could lead to vulnerabilities despite the lack of historical issues. The plugin's strengths lie in its limited attack surface and secure database interaction, while its primary weakness is the insufficient sanitization of output, posing a direct risk of XSS.
Key Concerns
- Low percentage of properly escaped output
CellarWeb User Profile Access Control Security Vulnerabilities
CellarWeb User Profile Access Control Code Analysis
Output Escaping
CellarWeb User Profile Access Control Attack Surface
WordPress Hooks 14
Maintenance & Trust
CellarWeb User Profile Access Control Maintenance & Trust
Maintenance Signals
Community Trust
CellarWeb User Profile Access Control Alternatives
No alternatives data available yet.
CellarWeb User Profile Access Control Developer Profile
16 plugins · 1K total installs
How We Detect CellarWeb User Profile Access Control
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cellarweb-user-profile-access-control/css/settings.csscellarweb-user-profile-access-control/css/settings.css?ver=HTML / DOM Fingerprints
CWUPAC_optionsCWUPAC_sidebarname="cellarweb_upac_option_name[cwupac_profile_block]"id="cwupac_profile_block"name="cellarweb_upac_option_name[cwupac_send_notice]"id="cwupac_send_notice"