Customize/edit wp-signup (registration) for wpms Security & Risk Analysis

wordpress.org/plugins/customize-edit-wp-signup-registration-for-wpms

Make a smaller wp-signup in the top of your site, that works for wpms, allowing website registration and even integrated with "New blog templates …

10 active installs v1.0.1 PHP + WP 3.0.1+ Updated Jun 13, 2014
customize-registrationedit-registrationjquery-wp-signupsmaller-wp-signupwp-signup
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Customize/edit wp-signup (registration) for wpms Safe to Use in 2026?

Generally Safe

Score 85/100

Customize/edit wp-signup (registration) for wpms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The plugin "customize-edit-wp-signup-registration-for-wpms" v1.0.1 exhibits a generally strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events, along with zero dangerous functions and no external HTTP requests, significantly limits the potential attack surface. Furthermore, the fact that all SQL queries utilize prepared statements is a positive indicator of secure database interaction.

However, a critical concern arises from the output escaping. With 3 total outputs and 0% properly escaped, this represents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any data that is displayed to users without proper sanitization or encoding could be manipulated to inject malicious scripts. The lack of nonce and capability checks across all entry points also presents a weakness, as it implies that any functionality exposed could potentially be accessed and exploited by unauthenticated or unauthorized users, especially if the limited attack surface were to be expanded or if vulnerabilities in other areas were discovered.

Given the complete absence of recorded vulnerabilities in its history, it's difficult to infer long-term patterns. However, the current analysis highlights a disconnect between the limited attack surface and the critical oversight in output sanitization. While the plugin appears well-contained and uses secure database practices, the unescaped output represents a clear and present danger that needs immediate attention.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Customize/edit wp-signup (registration) for wpms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Customize/edit wp-signup (registration) for wpms Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Customize/edit wp-signup (registration) for wpms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

Customize/edit wp-signup (registration) for wpms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwp_footerinsert-it-at-head.php:20
actionsignup_extra_fieldsinsert-it-at-head.php:21
actionsignup_finishedinsert-it-at-head.php:22
Maintenance & Trust

Customize/edit wp-signup (registration) for wpms Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedJun 13, 2014
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Customize/edit wp-signup (registration) for wpms Developer Profile

diegpl

6 plugins · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Customize/edit wp-signup (registration) for wpms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/customize-edit-wp-signup-registration-for-wpms/signup-style.css/wp-content/plugins/customize-edit-wp-signup-registration-for-wpms/edit-wp-signup.js/wp-content/plugins/customize-edit-wp-signup-registration-for-wpms/watermark/jquery.watermark.js
Script Paths
edit-wp-signup.jswatermark/jquery.watermark.js
Version Parameters
customize-edit-wp-signup-registration-for-wpms/signup-style.css?ver=customize-edit-wp-signup-registration-for-wpms/edit-wp-signup.js?ver=customize-edit-wp-signup-registration-for-wpms/watermark/jquery.watermark.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Customize/edit wp-signup (registration) for wpms