
For Users Only Security & Risk Analysis
wordpress.org/plugins/for-users-onlyAllows only logged in users to visit the site.
Is For Users Only Safe to Use in 2026?
Generally Safe
Score 100/100For Users Only has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "for-users-only" v1.1 exhibits a strong security posture based on the provided static analysis and vulnerability history. The static analysis reveals no discernible attack surface through AJAX, REST API, shortcodes, or cron events, and importantly, all identified code signals indicate adherence to secure coding practices. There are no dangerous functions used, all SQL queries utilize prepared statements, and all outputs are properly escaped. Furthermore, no file operations or external HTTP requests are made, and there's an absence of nonce and capability checks, which, while seemingly concerning, aligns with the overall lack of exposed entry points. The taint analysis also shows no flows with unsanitized paths, indicating a clean internal data handling process. The plugin's vulnerability history is spotless, with zero known CVEs, indicating a history of secure development or a lack of historical exploitation. This combination of minimal attack surface, adherence to secure coding principles, and a clean vulnerability record suggests a well-developed and secure plugin. The primary weakness, if it can be called that, is the complete lack of nonces and capability checks, which are typically present even in secure plugins as a defensive measure. However, given the absence of any identified entry points, this absence doesn't translate to an immediate, exploitable risk in the current analysis.
Key Concerns
- No nonce checks implemented
- No capability checks implemented
For Users Only Security Vulnerabilities
For Users Only Code Analysis
For Users Only Attack Surface
WordPress Hooks 2
Maintenance & Trust
For Users Only Maintenance & Trust
Maintenance Signals
Community Trust
For Users Only Alternatives
Expire User Passwords
expire-user-passwords
Require certain users to change their passwords on a regular basis.
Prevent Concurrent Logins
prevent-concurrent-logins
Prevents users from staying logged into the same account from multiple places.
LH Membership Numbers
lh-membership-numbers
Plugin to allow users to login by a number, their user ID (optionally prefixed)
WP-Members Membership Plugin
wp-members
The original WordPress membership plugin with content restriction, user login, custom registration fields, user profiles, and more.
Simple Membership After Login Redirection
simple-membership-after-login-redirection
An addon for the simple membership plugin to configure after login redirection to a specific page based on the member's level.
For Users Only Developer Profile
8 plugins · 65K total installs
How We Detect For Users Only
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/for-users-only/css/users-only-styles.css/wp-content/plugins/for-users-only/js/users-only.js/wp-content/plugins/for-users-only/js/users-only.jsfor-users-only/css/users-only-styles.css?ver=for-users-only/js/users-only.js?ver=HTML / DOM Fingerprints
users-only-login-form