
Faces of Users Security & Risk Analysis
wordpress.org/plugins/faces-of-usersDisplay registered users Gravatars on a single page with shortcode.
Is Faces of Users Safe to Use in 2026?
Generally Safe
Score 85/100Faces of Users has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "faces-of-users" plugin v0.0.3 exhibits a generally good security posture based on the provided static analysis. The absence of critical or high severity taint flows, dangerous functions, file operations, and properly escaped output are significant strengths. Furthermore, the lack of any recorded vulnerabilities in its history suggests a stable and well-maintained codebase. The plugin also boasts a very small attack surface, with only one shortcode as an entry point, and importantly, no unprotected entry points detected.
However, there are areas for concern that prevent a perfect score. The plugin utilizes raw SQL queries without prepared statements, which is a significant risk. While the static analysis did not detect unsanitized paths or critical taint flows in this instance, un-prepared SQL queries are a common vector for SQL injection vulnerabilities if user input is ever incorporated indirectly or directly into these queries. The lack of nonce checks and capability checks on its single shortcode is also a notable weakness. While it's not an AJAX or REST API endpoint, shortcodes can still be triggered in various ways, and without proper authorization or nonce validation, they could potentially be exploited.
In conclusion, the plugin has a solid foundation with minimal known risks and a clean vulnerability history. The primary areas for improvement lie in addressing the use of raw SQL and implementing proper authorization and nonce checks for its shortcode. Addressing these would elevate its security significantly.
Key Concerns
- Raw SQL queries without prepared statements
- Missing nonce checks on shortcode
- Missing capability checks on shortcode
Faces of Users Security Vulnerabilities
Faces of Users Code Analysis
SQL Query Safety
Faces of Users Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Faces of Users Maintenance & Trust
Maintenance Signals
Community Trust
Faces of Users Alternatives
User Access Shortcodes
user-access-shortcodes
The simplest way of controlling who sees what in your posts/pages. Restrict content to logged in users only (or guests, or by roles) with simple short …
AnnunciFunebri
annuncifunebri-onoranza
Display funeral announcements from annuncifunebri.it on your website for funeral homes using this service.
AddFunc Adaptive Content
addfunc-adaptive-content
Adds functions, shortcodes & quicktags to empower WordPress users to have better control of when content is served, based on device.
BP XProfile Shortcode
bp-xprofile-shortcode
Adds Shortcode for BuddyPress XProfile data
Dob Easy Shortcode
dob-easy-shortcoder
DOB Shortcoder allows you to create any shortcode and easily modify it's content. No coding skills needed.
Faces of Users Developer Profile
5 plugins · 1K total installs
How We Detect Faces of Users
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/faces-of-users/faces-of.cssHTML / DOM Fingerprints
facesofusersid="facesofusers"[facesofusers]<div class="facesofusers"><img src="http://www.gravatar.com/avatar/<a href="