Fullworks Active Users Monitor Security & Risk Analysis

wordpress.org/plugins/fullworks-active-users-monitor

Real-time monitoring of logged-in WordPress users with visual indicators, filtering, and comprehensive admin tools.

30 active installs v1.1.0 PHP 7.4+ WP 6.2+ Updated Sep 17, 2025
active-usersadmin-toolsmonitoringonline-usersusers
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Fullworks Active Users Monitor Safe to Use in 2026?

Generally Safe

Score 100/100

Fullworks Active Users Monitor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The plugin "fullworks-active-users-monitor" v1.1.0 demonstrates a strong security posture based on the provided static analysis. A significant number of capability and nonce checks are in place, and the vast majority of SQL queries and output operations are properly handled with prepared statements and escaping, respectively. The absence of known vulnerabilities and critical taint flows is also highly encouraging. The plugin has no external HTTP requests and no bundled libraries, further reducing its potential attack surface. The total entry points are protected by authentication, and there are no unpatched CVEs in its history. This indicates a developer who is likely aware of and actively implementing security best practices. The only area that warrants minor attention is the presence of two unsanitized paths identified in the taint analysis, although they did not escalate to critical or high severity.

Key Concerns

  • Flows with unsanitized paths
Vulnerabilities
None known

Fullworks Active Users Monitor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Fullworks Active Users Monitor Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
26 prepared
Unescaped Output
8
235 escaped
Nonce Checks
7
Capability Checks
17
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

93% prepared28 total queries

Output Escaping

97% escaped243 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

7 flows2 with unsanitized paths
handle_export_request (includes\class-audit-exporter.php:31)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Fullworks Active Users Monitor Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 6

authwp_ajax_fwaum_update_admin_barincludes\class-admin-bar.php:42
authwp_ajax_fwaum_get_online_usersincludes\class-ajax-handler.php:37
authwp_ajax_fwaum_refresh_users_listincludes\class-ajax-handler.php:38
authwp_ajax_fwaum_get_user_statusincludes\class-ajax-handler.php:39
authwp_ajax_fwaum_audit_get_detailsincludes\class-audit-admin.php:27
authwp_ajax_fwaum_export_audit_logincludes\class-audit-exporter.php:25
WordPress Hooks 28
actionadmin_enqueue_scriptsfullworks-active-users-monitor.php:168
actionwp_enqueue_scriptsfullworks-active-users-monitor.php:169
actionadmin_initfullworks-active-users-monitor.php:178
actionplugins_loadedfullworks-active-users-monitor.php:276
actionadmin_bar_menuincludes\class-admin-bar.php:41
actionadmin_menuincludes\class-audit-admin.php:25
actionadmin_enqueue_scriptsincludes\class-audit-admin.php:26
actionwp_loginincludes\class-audit-logger.php:33
actionwp_logoutincludes\class-audit-logger.php:34
actionwp_login_failedincludes\class-audit-logger.php:35
actionauth_cookie_expiredincludes\class-audit-logger.php:36
actionfwaum_cleanup_audit_logsincludes\class-audit-logger.php:39
actionwp_dashboard_setupincludes\class-dashboard-widget.php:41
actionadmin_enqueue_scriptsincludes\class-dashboard-widget.php:42
actionadmin_menuincludes\class-settings.php:25
actionadmin_initincludes\class-settings.php:26
actioninitincludes\class-settings.php:27
actionwp_loginincludes\class-user-tracker.php:258
actionwp_logoutincludes\class-user-tracker.php:259
actionadmin_initincludes\class-users-list.php:37
filterviews_usersincludes\class-users-list.php:38
filterpre_get_usersincludes\class-users-list.php:39
filtermanage_users_columnsincludes\class-users-list.php:58
filtermanage_users_custom_columnincludes\class-users-list.php:59
filtermanage_users_sortable_columnsincludes\class-users-list.php:60
actionadmin_enqueue_scriptsincludes\class-users-list.php:63
actionadmin_noticesincludes\class-users-list.php:66
filteradmin_body_classincludes\class-users-list.php:349

Scheduled Events 1

fwaum_cleanup_audit_logs
Maintenance & Trust

Fullworks Active Users Monitor Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 17, 2025
PHP min version7.4
Downloads417

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Fullworks Active Users Monitor Developer Profile

fullworks

13 plugins · 79K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
1372 days
View full developer profile
Detection Fingerprints

How We Detect Fullworks Active Users Monitor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fullworks-active-users-monitor/assets/css/admin-style.css/wp-content/plugins/fullworks-active-users-monitor/assets/js/admin-script.js/wp-content/plugins/fullworks-active-users-monitor/assets/css/admin-bar.css
Script Paths
/wp-content/plugins/fullworks-active-users-monitor/assets/js/admin-script.js
Version Parameters
fullworks-active-users-monitor/assets/css/admin-style.css?ver=fullworks-active-users-monitor/assets/js/admin-script.js?ver=fullworks-active-users-monitor/assets/css/admin-bar.css?ver=

HTML / DOM Fingerprints

JS Globals
fwaumAjax
FAQ

Frequently Asked Questions about Fullworks Active Users Monitor