
DRegister Security & Risk Analysis
wordpress.org/plugins/dregisterEnhance your Registration Page. Require First Name, Last Name. Add custom fields. Require custom fields.
Is DRegister Safe to Use in 2026?
Generally Safe
Score 85/100DRegister has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "dregister" plugin version 1.3 presents a mixed security posture. On the positive side, there are no recorded vulnerabilities (CVEs) associated with this plugin, and the static analysis shows no dangerous functions, no direct SQL queries without prepared statements, and no external HTTP requests. This suggests a generally cautious approach to handling sensitive operations. However, significant concerns arise from the output escaping and taint analysis. A very low percentage of outputs (2%) are properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities where user-supplied data could be injected and executed by the browser. Furthermore, the taint analysis reveals two flows with unsanitized paths, which, while not classified as critical or high severity, still represent potential avenues for malicious data to enter and be processed without adequate validation. The absence of recorded vulnerabilities, coupled with these findings, might suggest that either the plugin's attack surface is very small, or that existing vulnerabilities have not yet been discovered or reported. While the lack of direct database manipulation risks and a history of no vulnerabilities are strengths, the pervasive issue with output escaping and the identified unsanitized taint flows are critical weaknesses that demand immediate attention.
Key Concerns
- Low output escaping percentage
- Unsanitized paths in taint analysis
DRegister Security Vulnerabilities
DRegister Code Analysis
Output Escaping
Data Flow Analysis
DRegister Attack Surface
WordPress Hooks 9
Maintenance & Trust
DRegister Maintenance & Trust
Maintenance Signals
Community Trust
DRegister Alternatives
ACF Woocommerce Account Fields
acf-woocommerce-account-fields
Add Advanced Custom Fields to the Woocommerce registration form and edit profile form.
Custom Registration Fields for WooCommerce
custom-registration-fields-for-woocommerce
Add custom registration fields to WooCommerce and WordPress user registration forms, capturing additional information from users with ease.
Advanced Members for ACF
advanced-members
A Lightweight & Powerful Membership Plugin for ACF Users. Seamlessly Use ACF Field Groups as Membership Forms
CIO Custom Fields for Woo
custom-fields-for-woo-customers
Simple and easy. Add unlimited custom fields in groups to registration, checkout, profile, my account & product pages with location rules*.
Ace User Management
ace-user-management
It help us to create registration form with unlimted custom fields.
DRegister Developer Profile
1 plugin · 10 total installs
How We Detect DRegister
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dregister/css/dregister.cssHTML / DOM Fingerprints
dr_input_radioid="dr_custom_input"