
KGR User Log Security & Risk Analysis
wordpress.org/plugins/kgr-user-logDisplays the registration time and the last active time in two custom columns in the users table.
Is KGR User Log Safe to Use in 2026?
Generally Safe
Score 92/100KGR User Log has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "kgr-user-log" v1.6.3 plugin exhibits a strong security posture based on the provided static analysis data. There are no identified dangerous functions, SQL queries are all prepared, and all output is properly escaped. Furthermore, the plugin does not perform file operations or external HTTP requests, significantly reducing its attack surface. The absence of any recorded vulnerabilities, historical or recent, further reinforces its current security standing.
However, the static analysis also highlights a critical lack of security checks, particularly concerning nonce checks and capability checks. With zero AJAX handlers, REST API routes, shortcodes, or cron events, the plugin has a seemingly minimal attack surface. Yet, the complete absence of nonce checks (0 total) on any potential entry points is a significant concern. While there is one capability check, its presence alone doesn't mitigate the risk if the entry points are not properly secured or if the capability check itself is insufficient.
In conclusion, while the code itself appears clean with no overt signs of dangerous practices or known vulnerabilities, the lack of fundamental security mechanisms like nonce checks on potential (even if currently none) entry points presents a latent risk. The plugin's strength lies in its minimal attack surface and adherence to good coding practices for queries and output. Its weakness lies in the complete absence of protective measures like nonce checks, which could be exploited if new entry points are introduced or if existing ones become exposed in future updates. The vulnerability history is excellent, but this does not excuse the absence of basic security layers.
Key Concerns
- Missing nonce checks on entry points
- Only one capability check present
KGR User Log Security Vulnerabilities
KGR User Log Code Analysis
Output Escaping
KGR User Log Attack Surface
WordPress Hooks 8
Maintenance & Trust
KGR User Log Maintenance & Trust
Maintenance Signals
Community Trust
KGR User Log Alternatives
No alternatives data available yet.
KGR User Log Developer Profile
4 plugins · 60 total installs
How We Detect KGR User Log
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kgr-user-log/column.csskgr-user-log/column.css?ver=