Elvez Control Access Security & Risk Analysis

wordpress.org/plugins/elvez-control-access

Control the access of non-logged-in users for each posts and pages.

10 active installs v1.1.4 PHP 7.2+ WP 5.2+ Updated Dec 6, 2021
accesscontrolloginredirectrestrict
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Elvez Control Access Safe to Use in 2026?

Generally Safe

Score 85/100

Elvez Control Access has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "elvez-control-access" v1.1.4 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the use of prepared statements for all SQL queries and the high percentage of properly escaped output are positive indicators of secure coding practices. The presence of a nonce check also suggests some attention to preventing CSRF-like attacks.

However, the complete lack of capability checks is a notable concern. While the attack surface is currently small and seemingly unprotected entry points are zero, this could become a significant risk if new features are added that introduce unprotected endpoints. The absence of any recorded vulnerabilities in its history is a positive sign, suggesting a history of relatively secure development. Despite the strengths, the lack of capability checks represents a potential weakness that could be exploited if the plugin were to gain more exposure or introduce more complex functionalities.

In conclusion, the plugin is currently in a good state, characterized by a small attack surface and good data handling practices. The primary area for improvement and potential future risk lies in the complete absence of capability checks, which could lead to unauthorized actions if the plugin evolves. The vulnerability history being clean is a strong positive, but the lack of capability checks warrants caution.

Key Concerns

  • Missing capability checks
Vulnerabilities
None known

Elvez Control Access Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Elvez Control Access Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
1
6 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

86% escaped7 total outputs
Attack Surface

Elvez Control Access Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 21
actionadmin_menuadmin\class-elvez-control-access-admin.php:112
actionsave_postadmin\class-elvez-control-access-admin.php:113
filtermanage_posts_columnsadmin\class-elvez-control-access-admin.php:115
filtermanage_pages_columnsadmin\class-elvez-control-access-admin.php:116
actionmanage_posts_custom_columnadmin\class-elvez-control-access-admin.php:117
actionmanage_pages_custom_columnadmin\class-elvez-control-access-admin.php:118
actionadmin_initadmin\class-elvez-control-access-admin.php:120
actionadmin_menuadmin\class-elvez-control-access-admin.php:121
actionplugins_loadedincludes\class-elvez-control-access.php:195
actionadmin_enqueue_scriptsincludes\class-elvez-control-access.php:210
actionadmin_enqueue_scriptsincludes\class-elvez-control-access.php:211
actionwp_enqueue_scriptsincludes\class-elvez-control-access.php:226
actionwp_enqueue_scriptsincludes\class-elvez-control-access.php:227
actiontemplate_redirectpublic\class-elvez-control-access-public.php:59
actionwppublic\class-elvez-control-access-public.php:60
actionpre_get_postspublic\class-elvez-control-access-public.php:62
filterget_pagespublic\class-elvez-control-access-public.php:63
filterwp_get_nav_menu_itemspublic\class-elvez-control-access-public.php:64
filterget_previous_post_wherepublic\class-elvez-control-access-public.php:65
filterget_next_post_wherepublic\class-elvez-control-access-public.php:66
actioninitpublic\class-elvez-control-access-public.php:68
Maintenance & Trust

Elvez Control Access Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedDec 6, 2021
PHP min version7.2
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Elvez Control Access Developer Profile

株式会社エルブズ

7 plugins · 180 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Elvez Control Access

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/elvez-control-access/css/elvez-control-access-admin.css/wp-content/plugins/elvez-control-access/js/elvez-control-access-admin.js
Script Paths
/wp-content/plugins/elvez-control-access/js/elvez-control-access-admin.js
Version Parameters
elvez-control-access/css/elvez-control-access-admin.css?ver=elvez-control-access/js/elvez-control-access-admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
name="elvez_control_access_restrict_access"id="elvez-control-access"
FAQ

Frequently Asked Questions about Elvez Control Access