
Force First and Last Name as Display Name Security & Risk Analysis
wordpress.org/plugins/force-first-lastForce the user field "display_name" to be set as the user's first and last name.
Is Force First and Last Name as Display Name Safe to Use in 2026?
Generally Safe
Score 92/100Force First and Last Name as Display Name has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'force-first-last' plugin v1.2.2 exhibits a generally good security posture based on the static analysis. There are no identified dangerous functions, file operations, or external HTTP requests. All identified output is properly escaped, and nonce and capability checks are present, indicating an effort to secure entry points. The absence of any critical or high severity taint flows is also a positive sign. However, a significant concern arises from the plugin's vulnerability history. It has a known medium severity CVE, and the fact that it was last patched in March 2023, with no indication of it being currently unpatched, suggests a potential for past vulnerabilities. The historical pattern of Cross-Site Request Forgery (CSRF) vulnerabilities, even if resolved, warrants vigilance as it indicates areas where improper input validation or insufficient authorization checks might have been previously exploited.
While the current static analysis shows a clean bill of health for the analyzed code signals and taint flows, the presence of a past CVE, specifically a medium severity one related to CSRF, should not be overlooked. This historical context suggests a weakness in how certain user actions or inputs were handled in previous versions, which could be a recurring theme if not addressed robustly. The plugin benefits from good output escaping and the presence of authorization checks. The main weakness lies in its past vulnerability history, hinting at potential areas of concern that, while seemingly resolved in this version, demand a degree of caution and ongoing monitoring.
Key Concerns
- Past medium severity CVE exists
- Raw SQL query without prepared statement
Force First and Last Name as Display Name Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Force First and Last Name as Display Name <= 1.2 - Cross-Site Request Forgery
Force First and Last Name as Display Name Release Timeline
Force First and Last Name as Display Name Code Analysis
SQL Query Safety
Output Escaping
Force First and Last Name as Display Name Attack Surface
WordPress Hooks 9
Maintenance & Trust
Force First and Last Name as Display Name Maintenance & Trust
Maintenance Signals
Community Trust
Force First and Last Name as Display Name Alternatives
Extended User Search In WP-Admin
extended-user-search-in-wp-admin
By default WordPress in WP-admin allows users to search only by username or email id.
Enhanced User Search
enhanced-user-search
Effortlessly find users in WordPress! Search by first & last name, username, or email.
Username Changer
username-changer
Unlock the power to change WordPress usernames with complete security and data integrity.
WS Force Login Page
ws-force-login-page
Redirecting user to login page if not logged in, working also with domains what includes umlaut letters like ö, ä, õ, ü
Login as User or Customer
login-as-customer-or-user
This plugin allows you to quickly swap between user accounts in WordPress (in one click). This is very helpful for admins or customer support users to …
Force First and Last Name as Display Name Developer Profile
7 plugins · 66K total installs
How We Detect Force First and Last Name as Display Name
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
ffl_adminjQuery