
Create User With Password Multisite Security & Risk Analysis
wordpress.org/plugins/create-user-with-password-multisiteAllow website administrators to allocate passwords to users as they add them to invidivual sites in WordPress Multisite.
Is Create User With Password Multisite Safe to Use in 2026?
Generally Safe
Score 100/100Create User With Password Multisite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "create-user-with-password-multisite" v1.10.0 demonstrates a strong security posture based on the provided static analysis. There are no identified dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. The absence of file operations and external HTTP requests further reduces the potential attack surface. Nonce and capability checks are present, indicating an awareness of WordPress security best practices for its entry points.
The static analysis reveals a minimal attack surface with zero AJAX handlers, REST API routes, shortcodes, or cron events. This means there are no direct entry points for attackers to exploit. Furthermore, the taint analysis shows no flows with unsanitized paths, and zero critical or high-severity issues. The plugin's vulnerability history is also clean, with no known CVEs, which suggests a history of secure development or a lack of past significant security incidents.
Overall, this plugin appears to be very secure with no immediately evident vulnerabilities. Its strengths lie in its limited attack surface, adherence to secure coding practices regarding data handling and output, and a clean security history. The primary weakness, if one can call it that given the data, is the very small number of total entry points, which might suggest limited functionality or that potential entry points are not being analyzed or are intentionally absent. However, based on the provided data, the plugin is robust.
Create User With Password Multisite Security Vulnerabilities
Create User With Password Multisite Release Timeline
Create User With Password Multisite Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Create User With Password Multisite Attack Surface
WordPress Hooks 6
Maintenance & Trust
Create User With Password Multisite Maintenance & Trust
Maintenance Signals
Community Trust
Create User With Password Multisite Alternatives
WordPass
wordpass
Creates word-based passwords for WordPress.
User Spam Remover
user-spam-remover
Automatically removes spam user registrations and other old, unused user accounts. Blocks annoying e-mail to administrator after new registrations.
Disable User Registration Notification Emails
disable-user-registration-notification-emails
Turns off the notification sent to the admin email when a new user account is registered. Works with WP >= 4.6.0.
Chap Secure Password Login
chap-secure-login
Do not show password, during login, on an insecure channel (without SSL). Use a SHA-256 hash algorithm.
Force Password Change
force-password-change
Require users to change their password on first login.
Create User With Password Multisite Developer Profile
6 plugins · 308K total installs
How We Detect Create User With Password Multisite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/create-user-with-password-multisite/css/style.css/wp-content/plugins/create-user-with-password-multisite/js/cuwp.jsHTML / DOM Fingerprints
hook-passpass-errorname="cuwp_security"value="cuwp"name="cuwp_pass1"name="cuwp_pass2"