
Elvez Control Access Security & Risk Analysis
wordpress.org/plugins/elvez-control-accessControl the access of non-logged-in users for each posts and pages.
Is Elvez Control Access Safe to Use in 2026?
Generally Safe
Score 85/100Elvez Control Access has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "elvez-control-access" v1.1.4 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the use of prepared statements for all SQL queries and the high percentage of properly escaped output are positive indicators of secure coding practices. The presence of a nonce check also suggests some attention to preventing CSRF-like attacks.
However, the complete lack of capability checks is a notable concern. While the attack surface is currently small and seemingly unprotected entry points are zero, this could become a significant risk if new features are added that introduce unprotected endpoints. The absence of any recorded vulnerabilities in its history is a positive sign, suggesting a history of relatively secure development. Despite the strengths, the lack of capability checks represents a potential weakness that could be exploited if the plugin were to gain more exposure or introduce more complex functionalities.
In conclusion, the plugin is currently in a good state, characterized by a small attack surface and good data handling practices. The primary area for improvement and potential future risk lies in the complete absence of capability checks, which could lead to unauthorized actions if the plugin evolves. The vulnerability history being clean is a strong positive, but the lack of capability checks warrants caution.
Key Concerns
- Missing capability checks
Elvez Control Access Security Vulnerabilities
Elvez Control Access Code Analysis
SQL Query Safety
Output Escaping
Elvez Control Access Attack Surface
WordPress Hooks 21
Maintenance & Trust
Elvez Control Access Maintenance & Trust
Maintenance Signals
Community Trust
Elvez Control Access Alternatives
Absoluto Access Gate
absoluto-access-gate
Force users to login before viewing pages. Exclude specific pages and allow certain user roles/users to bypass the requirement.
LCK cloud Connector
lck-cloud-connector
Easily restrict access to your existing WordPress pages and posts. Official connector to build secure membership sites with LCK cloud.
Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More
content-control
Restrict content based on login status, user roles, device type & more. Monetize your content with a paywall or members-only content.
Remove Dashboard Access
remove-dashboard-access-for-non-admins
Disable Dashboard access for users of a specific role or capability. Disallowed users are redirected to a chosen URL. Get set up in seconds.
Restrict User Access – Ultimate Membership & Content Protection
restrict-user-access
Create Access Levels and restrict any post, page, category, etc. Supports bbPress, BuddyPress, WooCommerce, WPML, and more.
Elvez Control Access Developer Profile
7 plugins · 180 total installs
How We Detect Elvez Control Access
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/elvez-control-access/css/elvez-control-access-admin.css/wp-content/plugins/elvez-control-access/js/elvez-control-access-admin.js/wp-content/plugins/elvez-control-access/js/elvez-control-access-admin.jselvez-control-access/css/elvez-control-access-admin.css?ver=elvez-control-access/js/elvez-control-access-admin.js?ver=HTML / DOM Fingerprints
name="elvez_control_access_restrict_access"id="elvez-control-access"