Manage User Columns Security & Risk Analysis

wordpress.org/plugins/manage-user-columns

This plugin allows you to manage columns under the users page in the WordPress admin area.

1K active installs v1.0.6 PHP 7.4+ WP 6.0+ Updated Jun 16, 2025
columnsfilterregistration-dateuser-columnusers
99
A · Safe
CVEs total1
Unpatched0
Last CVENov 1, 2024
Download
Safety Verdict

Is Manage User Columns Safe to Use in 2026?

Generally Safe

Score 99/100

Manage User Columns has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 1, 2024Updated 9mo ago
Risk Assessment

The 'manage-user-columns' plugin version 1.0.6 presents a mixed security posture. While it demonstrates some good practices such as the absence of dangerous functions, file operations, and external HTTP requests, significant concerns arise from its handling of entry points and data sanitization. The plugin exposes two AJAX handlers, both of which lack authentication checks. This, combined with two taint flows identified as having unsanitized paths and rated as high severity, creates a substantial risk. The historical vulnerability data, including a past medium-severity Cross-Site Request Forgery (CSRF) vulnerability, suggests a pattern of security weaknesses that require attention. The presence of raw SQL queries without prepared statements further exacerbates the risk of SQL injection. Although the plugin has no currently unpatched CVEs, the combination of unprotected entry points, high-severity unsanitized data flows, and historical vulnerabilities points to a need for significant security improvements to mitigate potential attacks.

Key Concerns

  • Unprotected AJAX handlers
  • High severity taint flows with unsanitized paths
  • SQL queries without prepared statements
  • Low percentage of properly escaped output
  • Historical medium CVE
Vulnerabilities
1

Manage User Columns Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-51686medium · 4.3Cross-Site Request Forgery (CSRF)

Manage User Columns <= 1.0.5 - Cross-Site Request Forgery

Nov 1, 2024 Patched in 1.0.6 (6d)
Code Analysis
Analyzed Mar 16, 2026

Manage User Columns Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
9
6 escaped
Nonce Checks
3
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

40% escaped15 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
dpk_muc_umeta_search (ajax-functions.php:10)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Manage User Columns Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_dpk_muc_umeta_searchajax-functions.php:7
noprivwp_ajax_dpk_muc_umeta_searchajax-functions.php:8
WordPress Hooks 8
actionplugins_loadedmanage-user-columns.php:18
actionadmin_enqueue_scriptsmanage-user-columns.php:22
filtermanage_users_columnsmanage-user-columns.php:23
filtermanage_users_custom_columnmanage-user-columns.php:24
filtermanage_users_sortable_columnsmanage-user-columns.php:25
actionload-users.phpmanage-user-columns.php:26
actionadmin_footermanage-user-columns.php:27
actionpre_get_usersmanage-user-columns.php:28
Maintenance & Trust

Manage User Columns Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 16, 2025
PHP min version7.4
Downloads19K

Community Trust

Rating84/100
Number of ratings5
Active installs1K
Developer Profile

Manage User Columns Developer Profile

Deepak Khokhar

6 plugins · 5K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
236 days
View full developer profile
Detection Fingerprints

How We Detect Manage User Columns

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/manage-user-columns/style.css/wp-content/plugins/manage-user-columns/main.js
Script Paths
/wp-content/plugins/manage-user-columns/main.js
Version Parameters
manage-user-columns/style.css?ver=manage-user-columns/main.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-col_iddata-col_namedata-col_val
JS Globals
ajax_dpk_muc_obj
FAQ

Frequently Asked Questions about Manage User Columns