
Featured Users Security & Risk Analysis
wordpress.org/plugins/featured-users-wordpress-pluginAllows the administrator to make users featured. All it does is give the user a custom meta field called jsfeatured_user. Now available are a shortcod …
Is Featured Users Safe to Use in 2026?
Generally Safe
Score 85/100Featured Users has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "featured-users-wordpress-plugin" v2.1 exhibits a generally positive security posture, with no known vulnerabilities in its history and a strong adherence to several best practices. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are all commendable. Furthermore, the presence of nonce and capability checks, along with a clean taint analysis, suggest a well-developed plugin. However, a significant concern arises from the output escaping. With 39% of outputs properly escaped, a considerable portion (61%) remains unescaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without proper sanitization, particularly in features exposed through its AJAX handler or shortcode. While the attack surface is small and entry points are protected, the lack of comprehensive output escaping is a notable weakness that requires attention.
Key Concerns
- Insufficient output escaping
Featured Users Security Vulnerabilities
Featured Users Code Analysis
Output Escaping
Featured Users Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
Featured Users Maintenance & Trust
Maintenance Signals
Community Trust
Featured Users Alternatives
User Switching
user-switching
Instant switching between user accounts in WordPress and WooCommerce.
One User Avatar | User Profile Picture
one-user-avatar
Use any image from your WordPress Media Library as a custom user avatar or user profile picture. Add your own Default Avatar.
Simple Local Avatars
simple-local-avatars
Adds an avatar upload field to user profiles. Generates requested sizes on demand just like Gravatar!
Featured Image from URL (FIFU)
featured-image-from-url
Use remote media as the featured image and beyond.
Export and Import Users and Customers
users-customers-import-export-for-wp-woocommerce
Import and export WordPress users and WooCommerce customers using CSV. Migrate to your new site without any data loss.
Featured Users Developer Profile
3 plugins · 120 total installs
How We Detect Featured Users
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/featured-users-wordpress-plugin/js/featured-users.js/wp-content/plugins/featured-users-wordpress-plugin/css/featured-users.css/wp-content/plugins/featured-users-wordpress-plugin/js/featured-users.jsfeatured-users-wordpress-plugin/js/featured-users.js?ver=featured-users-wordpress-plugin/css/featured-users.css?ver=HTML / DOM Fingerprints
featured-user-avatarfeatured-user-display-namefeatured-user-description$ <a href="https://www.reactivedevelopment.net/contact/project-mind/?plugin=featured-users" target="_blank">Paid support</a>♥ <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=RESFMU9LDAEDQ&source=url" target="_blank">Donate</a>data-iddata-actionfeatured_users_ajax_object[rd-featured-users