Direct Password Reset Link | Share a password reset link to the user Security & Risk Analysis

wordpress.org/plugins/direct-password-reset-link

It shows you a password reset link in the user profile page and in the users list page.

100 active installs v0.0.2 PHP 7.2+ WP 4.6+ Updated Dec 10, 2025
forgot-passwordprofileuser
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Direct Password Reset Link | Share a password reset link to the user Safe to Use in 2026?

Generally Safe

Score 100/100

Direct Password Reset Link | Share a password reset link to the user has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The direct-password-reset-link plugin v0.0.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, or taint flows suggests a diligent approach to secure coding practices. Furthermore, the plugin has no recorded vulnerability history, which indicates a lack of past security incidents and potentially a well-maintained codebase.

While the attack surface appears minimal with zero entry points and no explicitly unprotected handlers or routes, the lack of nonce checks is a notable concern. Although the capability checks are present, the absence of nonce verification on potential AJAX or other interactive components, if they were to exist, could open doors for Cross-Site Request Forgery (CSRF) attacks. The overall absence of identified vulnerabilities and the good code signals are positive, but the oversight regarding nonce checks warrants attention.

In conclusion, the plugin demonstrates good fundamental security in its current state with no critical or high-risk issues identified in static analysis or vulnerability history. However, the lack of nonce checks represents a potential weakness that could be exploited in certain scenarios. Addressing this could further solidify its security profile.

Key Concerns

  • Missing nonce checks
Vulnerabilities
None known

Direct Password Reset Link | Share a password reset link to the user Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Direct Password Reset Link | Share a password reset link to the user Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
7 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped7 total outputs
Attack Surface

Direct Password Reset Link | Share a password reset link to the user Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionedit_user_profiledirect-password-reset-link.php:22
filteruser_row_actionsdirect-password-reset-link.php:50
Maintenance & Trust

Direct Password Reset Link | Share a password reset link to the user Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 10, 2025
PHP min version7.2
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Direct Password Reset Link | Share a password reset link to the user Developer Profile

Jose Mortellaro

56 plugins · 26K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
62 days
View full developer profile
Detection Fingerprints

How We Detect Direct Password Reset Link | Share a password reset link to the user

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
user-generate-reset-link-wrap
JS Globals
password_reset_link_initpswWrpresetLinkWrp
FAQ

Frequently Asked Questions about Direct Password Reset Link | Share a password reset link to the user