
Codup Read Only Admin Security & Risk Analysis
wordpress.org/plugins/codup-read-only-adminThis plugins allows to create an admin with read only access.
Is Codup Read Only Admin Safe to Use in 2026?
Generally Safe
Score 85/100Codup Read Only Admin has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "codup-read-only-admin" plugin v1.1.1.8 exhibits a generally strong security posture based on the static analysis. The complete absence of dangerous functions, file operations, external HTTP requests, and SQL queries executed without prepared statements are significant strengths. Furthermore, all identified output is properly escaped, and a reasonable number of capability checks are in place, indicating good awareness of secure coding practices.
Despite the positive static analysis, a known medium severity Cross-Site Scripting (XSS) vulnerability from May 2022 remains a notable concern, even though it is marked as patched. While the static analysis didn't reveal any new taint flows or critical vulnerabilities, the presence of a past XSS flaw suggests that input validation might be an area that requires ongoing vigilance. The plugin's limited attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed without checks, significantly mitigates immediate risks.
In conclusion, the plugin is well-coded with sound security practices for new development. However, the historical XSS vulnerability, even if patched, serves as a reminder of the importance of thorough input sanitization and the need for continuous security auditing, especially for plugins that handle sensitive administrative functions. The lack of critical findings in the current static analysis is reassuring, but the past vulnerability warrants a slightly cautious approach.
Key Concerns
- Past medium severity XSS vulnerability
Codup Read Only Admin Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Codup Read Only Admin <= 1.1.1.7 - Cross Site Scripting
Codup Read Only Admin Release Timeline
Codup Read Only Admin Code Analysis
Output Escaping
Codup Read Only Admin Attack Surface
WordPress Hooks 25
Maintenance & Trust
Codup Read Only Admin Maintenance & Trust
Maintenance Signals
Community Trust
Codup Read Only Admin Alternatives
No alternatives data available yet.
Codup Read Only Admin Developer Profile
2 plugins · 120 total installs
How We Detect Codup Read Only Admin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/codup-read-only-admin/assets/css/style.cssHTML / DOM Fingerprints
CROA_PLUGIN_DIR_URL