Codup Read Only Admin Security & Risk Analysis

wordpress.org/plugins/codup-read-only-admin

This plugins allows to create an admin with read only access.

100 active installs v1.1.1.8 PHP + WP 4.4+ Updated Apr 27, 2022
admin-roleread-only-access
85
A · Safe
CVEs total1
Unpatched0
Last CVEMay 25, 2022
Download
Safety Verdict

Is Codup Read Only Admin Safe to Use in 2026?

Generally Safe

Score 85/100

Codup Read Only Admin has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: May 25, 2022Updated 4yr ago
Risk Assessment

The "codup-read-only-admin" plugin v1.1.1.8 exhibits a generally strong security posture based on the static analysis. The complete absence of dangerous functions, file operations, external HTTP requests, and SQL queries executed without prepared statements are significant strengths. Furthermore, all identified output is properly escaped, and a reasonable number of capability checks are in place, indicating good awareness of secure coding practices.

Despite the positive static analysis, a known medium severity Cross-Site Scripting (XSS) vulnerability from May 2022 remains a notable concern, even though it is marked as patched. While the static analysis didn't reveal any new taint flows or critical vulnerabilities, the presence of a past XSS flaw suggests that input validation might be an area that requires ongoing vigilance. The plugin's limited attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed without checks, significantly mitigates immediate risks.

In conclusion, the plugin is well-coded with sound security practices for new development. However, the historical XSS vulnerability, even if patched, serves as a reminder of the importance of thorough input sanitization and the need for continuous security auditing, especially for plugins that handle sensitive administrative functions. The lack of critical findings in the current static analysis is reassuring, but the past vulnerability warrants a slightly cautious approach.

Key Concerns

  • Past medium severity XSS vulnerability
Vulnerabilities
1 published

Codup Read Only Admin Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-c2760f65-a981-42f6-b18c-fcf493bd34b6-codup-read-only-adminmedium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Codup Read Only Admin <= 1.1.1.7 - Cross Site Scripting

May 25, 2022 Patched in 1.1.1.8 (608d)
Version History

Codup Read Only Admin Release Timeline

Code Analysis
Analyzed Mar 16, 2026

Codup Read Only Admin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

Codup Read Only Admin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 25
actionpre_get_postsincludes\class-core.php:14
actionadmin_initincludes\class-core.php:15
actionadmin_menuincludes\class-core.php:16
actionuser_new_formincludes\class-core.php:17
actionshow_user_profileincludes\class-core.php:18
actionedit_user_profileincludes\class-core.php:19
actionuser_registerincludes\class-core.php:20
actionpersonal_options_updateincludes\class-core.php:21
actionedit_user_profile_updateincludes\class-core.php:22
actionadmin_headincludes\class-core.php:23
filterallowed_block_typesincludes\class-core.php:24
actionadd_meta_boxesincludes\class-core.php:25
filterpre_site_transient_update_pluginsincludes\class-core.php:150
filterpre_site_transient_update_themesincludes\class-core.php:151
filterbulk_actions-edit-postincludes\class-core.php:223
filterbulk_actions-edit-commentsincludes\class-core.php:224
filterbulk_actions-usersincludes\class-core.php:225
filterbulk_actions-pluginsincludes\class-core.php:226
filterbulk_actions-uploadincludes\class-core.php:227
filterpost_row_actionsincludes\class-core.php:238
filterpage_row_actionsincludes\class-core.php:239
filtermedia_row_actionsincludes\class-core.php:240
filtercomment_row_actionsincludes\class-core.php:241
filteruser_row_actionsincludes\class-core.php:242
filterplugin_action_linksincludes\class-core.php:243
Maintenance & Trust

Codup Read Only Admin Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedApr 27, 2022
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Alternatives

Codup Read Only Admin Alternatives

No alternatives data available yet.

Developer Profile

Codup Read Only Admin Developer Profile

codup

2 plugins · 120 total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
622 days
View full developer profile
Detection Fingerprints

How We Detect Codup Read Only Admin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/codup-read-only-admin/assets/css/style.css

HTML / DOM Fingerprints

JS Globals
CROA_PLUGIN_DIR_URL
FAQ

Frequently Asked Questions about Codup Read Only Admin