
Extended Super Admins Security & Risk Analysis
wordpress.org/plugins/extended-super-adminsThis plugin allows you to create multiple levels of Super Admins in a multi-site configuration.
Is Extended Super Admins Safe to Use in 2026?
Generally Safe
Score 85/100Extended Super Admins has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "extended-super-admins" plugin v0.7b demonstrates a generally positive security posture based on the static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface, and all identified entry points appear to be protected by authentication checks. The code also incorporates a reasonable number of nonce and capability checks, suggesting an awareness of common WordPress security practices. Furthermore, the plugin has no recorded vulnerability history, which is a strong indicator of its current security maturity.
However, there are areas for concern. The very low percentage of properly escaped output (6%) is a significant weakness. This suggests that user-supplied data or dynamic content might be rendered directly to the browser without sufficient sanitization, potentially opening the door to Cross-Site Scripting (XSS) vulnerabilities. While the taint analysis found no unsanitized flows, this could be a limitation of the analysis itself, especially given the poor output escaping. The fact that 40% of SQL queries are not using prepared statements also presents a risk of SQL injection, though the taint analysis did not flag any specific issues here.
In conclusion, while the plugin benefits from a small attack surface and a clean vulnerability history, the poor output escaping and the use of raw SQL queries are significant concerns that should be addressed to improve its overall security. The plugin is currently in a beta version (v0.7b), which may explain some of these less-than-ideal practices, but these areas require attention before a stable release.
Key Concerns
- Low output escaping percentage
- SQL queries not using prepared statements
Extended Super Admins Security Vulnerabilities
Extended Super Admins Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Extended Super Admins Attack Surface
WordPress Hooks 9
Maintenance & Trust
Extended Super Admins Maintenance & Trust
Maintenance Signals
Community Trust
Extended Super Admins Alternatives
Advanced Export for WP & WPMU
advanced-export-for-wp-wpmu
Adds an Advanced Export to the Tools menu which allows selective exporting of pages, posts, specific categories and/or post statuses by date.
Multisite Plugin Manager
multisite-plugin-manager
The essential plugin for every multisite install! Manage plugin access permissions across your entire multisite network.
Multisite Cloner
multisite-cloner
When creating a new blog on WordPress Multisite, copies all the posts, settings and files, from a selected blog into the new one.
Multisite User Role Manager
multisite-user-role-manager
Manage user roles for each blog from a single screen on multisite (WPMU) setups
Network Username Restrictions Override
network-username-restrictions-override
Override restrictions on WordPress network usernames.
Extended Super Admins Developer Profile
8 plugins · 2K total installs
How We Detect Extended Super Admins
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/extended-super-admins/css/extended_super_admins.css/wp-content/plugins/extended-super-admins/js/extended_super_admins.js/wp-content/plugins/extended-super-admins/js/extended_super_admins.jsextended-super-admins/css/extended_super_admins.css?ver=extended-super-admins/js/extended_super_admins.js?ver=HTML / DOM Fingerprints
_role_caps_single_capesa-notice<!-- Extended Super Admins --><!-- Extended Super Admins Settings --><!-- Extended Super Admins Roles -->data-esa-role-iddata-esa-role-nameESAesa_admin_vars