Deactivate WordPress Users Security & Risk Analysis

wordpress.org/plugins/deactivate-users

Allows admins to deactivate a user as opposed to deleting a user. Works with web and XML-RPC based authentication.

10 active installs v1.1 PHP + WP 3.0.1+ Updated Jun 20, 2014
authenticationdeactivatedisableuserusers
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Deactivate WordPress Users Safe to Use in 2026?

Generally Safe

Score 85/100

Deactivate WordPress Users has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "deactivate-users" plugin v1.1 exhibits a strong security posture based on the provided static analysis. There are no identified dangerous functions, all SQL queries utilize prepared statements, and output escaping is complete. Furthermore, the absence of file operations, external HTTP requests, and a very limited attack surface (zero AJAX handlers, REST API routes, shortcodes, or cron events) significantly reduce the potential for exploitation. The presence of one capability check further indicates a degree of authorization awareness in the codebase.

The vulnerability history is equally reassuring, showing zero known CVEs, currently unpatched vulnerabilities, or any recorded common vulnerability types. This lack of past security incidents, coupled with the clean static analysis, suggests a well-developed and secure plugin.

However, the complete absence of nonce checks and the single capability check, while not directly indicative of a vulnerability in this specific version given the zero attack surface, represent a potential area for concern if the plugin were to evolve and introduce more interactive features. The current analysis suggests a highly secure plugin, but it's important to maintain vigilance for future updates.

Vulnerabilities
None known

Deactivate WordPress Users Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Deactivate WordPress Users Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Deactivate WordPress Users Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Deactivate WordPress Users Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actioninitdeactivate-users.php:32
filtercmb_meta_boxesdeactivate-users.php:33
filterauthenticatedeactivate-users.php:34
Maintenance & Trust

Deactivate WordPress Users Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedJun 20, 2014
PHP min version
Downloads2K

Community Trust

Rating80/100
Number of ratings1
Active installs10
Developer Profile

Deactivate WordPress Users Developer Profile

Eric Binnion

5 plugins · 50 total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Deactivate WordPress Users

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
data-id="_deactivate_user_meta"
FAQ

Frequently Asked Questions about Deactivate WordPress Users