Multisite Edit My Sites Security & Risk Analysis

wordpress.org/plugins/multisite-edit-my-sites

For Multisite, Edit the role of all sites for the user from the network user edit screen.

0 active installs v1.0.0 PHP + WP 4.4.0+ Updated Aug 16, 2019
multisitesiteuser
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Multisite Edit My Sites Safe to Use in 2026?

Generally Safe

Score 85/100

Multisite Edit My Sites has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The static analysis of the "multisite-edit-my-sites" v1.0.0 plugin reveals a generally positive security posture. The plugin demonstrates strong adherence to secure coding practices by exhibiting zero AJAX handlers, REST API routes, shortcodes, or cron events. Crucially, all detected SQL queries utilize prepared statements, and all output operations are properly escaped, indicating no immediate risks of SQL injection or Cross-Site Scripting (XSS) vulnerabilities stemming from these common attack vectors. Furthermore, the absence of file operations and external HTTP requests reduces the plugin's exposure to file manipulation or remote code execution risks. The lack of any recorded vulnerabilities in its history, including critical or high severity ones, further supports a conclusion of good security hygiene. However, the analysis also highlights a significant lack of built-in security checks, specifically zero nonces and zero capability checks. While the current version has a minimal attack surface, this absence of authorization and authentication mechanisms on potential (though currently non-existent) entry points is a concern. If future updates introduce new features that create an attack surface, these essential security layers will be missing, leaving them unprotected by default. The plugin currently relies on its lack of exposed functionality for security, which is a fragile approach.

Key Concerns

  • No nonce checks on potential entry points
  • No capability checks on potential entry points
Vulnerabilities
None known

Multisite Edit My Sites Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Multisite Edit My Sites Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
17 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped17 total outputs
Attack Surface

Multisite Edit My Sites Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedmultisite-edit-my-sites.php:24
actionedit_user_profilemultisite-edit-my-sites.php:26
actionprofile_updatemultisite-edit-my-sites.php:30
actionadmin_initmultisite-edit-my-sites.php:32
Maintenance & Trust

Multisite Edit My Sites Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedAug 16, 2019
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Multisite Edit My Sites Developer Profile

hijiri

3 plugins · 400K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
364 days
View full developer profile
Detection Fingerprints

How We Detect Multisite Edit My Sites

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/multisite-edit-my-sites/css/style.css/wp-content/plugins/multisite-edit-my-sites/js/script.js
Script Paths
/wp-content/plugins/multisite-edit-my-sites/js/script.js
Version Parameters
multisite-edit-my-sites/js/script.js?ver=1.0multisite-edit-my-sites/css/style.css?ver=1.0

HTML / DOM Fingerprints

CSS Classes
hmems
Data Attributes
name="hmems_all_select"id="hmems_all_apply"name="hmems_checkid="hmems_check_name="users_sites
FAQ

Frequently Asked Questions about Multisite Edit My Sites