
Moving Users Security & Risk Analysis
wordpress.org/plugins/moving-usersSupports the transfer of Users between servers.
Is Moving Users Safe to Use in 2026?
Generally Safe
Score 99/100Moving Users has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis for the "moving-users" plugin v1.11 reveals a generally good security posture concerning its direct attack surface and output handling. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, significantly minimizing the plugin's exposure points. Furthermore, all identified output operations are properly escaped, and no dangerous functions, file operations, or external HTTP requests were detected. The absence of taint analysis issues is also a positive sign, indicating no immediate concerns with unsanitized data flows within the analyzed code.
However, the plugin's vulnerability history is a significant concern. With one known medium-severity CVE categorized as 'Exposure of Sensitive Information to an Unauthorized Actor', even though it's currently patched, it highlights a past weakness in how sensitive information was handled. The fact that this is the *only* vulnerability but of this nature suggests a potential blind spot in the plugin's security, particularly around data protection. The absence of any capability checks or nonce checks in the code analysis, combined with the past sensitive information exposure, raises a flag about the robustness of authorization and session validation, even if the current attack surface is small.
In conclusion, while the current version of "moving-users" v1.11 demonstrates strong adherence to secure coding practices for its visible attack surface and output handling, the historical vulnerability regarding sensitive information exposure, coupled with the lack of explicit capability and nonce checks, warrants caution. This indicates that while the immediate risks may be low due to the limited entry points, the plugin's underlying mechanisms for data protection and authorization might not be as robust as desired, suggesting a moderate overall risk. It's crucial for users to remain vigilant and ensure the plugin is always updated to the latest version to benefit from past vulnerability fixes.
Key Concerns
- One medium CVE for sensitive info exposure
- No nonce checks on entry points
- No capability checks on entry points
- 1 SQL query not using prepared statements
Moving Users Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Moving Users <= 1.05 - Unauthenticated Sensitive Information Exposure
Moving Users Code Analysis
SQL Query Safety
Moving Users Attack Surface
Maintenance & Trust
Moving Users Maintenance & Trust
Maintenance Signals
Community Trust
Moving Users Alternatives
User Switching
user-switching
Instant switching between user accounts in WordPress and WooCommerce.
One User Avatar | User Profile Picture
one-user-avatar
Use any image from your WordPress Media Library as a custom user avatar or user profile picture. Add your own Default Avatar.
Simple Local Avatars
simple-local-avatars
Adds an avatar upload field to user profiles. Generates requested sizes on demand just like Gravatar!
Export and Import Users and Customers
users-customers-import-export-for-wp-woocommerce
Import and export WordPress users and WooCommerce customers using CSV. Migrate to your new site without any data loss.
User Profile Picture
metronet-profile-picture
Set a custom profile image (avatar) for a user using the standard WordPress media upload tool.
Moving Users Developer Profile
52 plugins · 56K total installs
How We Detect Moving Users
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/moving-users/asset/css/moving-users.css/wp-content/plugins/moving-users/asset/js/moving-users.js/wp-content/plugins/moving-users/asset/js/moving-users-admin.js/wp-content/plugins/moving-users/asset/js/moving-users.js/wp-content/plugins/moving-users/asset/js/moving-users-admin.jsmoving-users/asset/css/moving-users.css?ver=moving-users/asset/js/moving-users.js?ver=moving-users/asset/js/moving-users-admin.js?ver=HTML / DOM Fingerprints
moving-users-wrapmoving-users-noticedata-movingusers-id