
Multisite Logout Users Security & Risk Analysis
wordpress.org/plugins/multisite-logout-all-usersRequires Wordpress Multisite Installation Stable Tag: 1.0 License: GPLv3 License URI: http://www.gnu.org/licenses/gpl-3.0.html
Is Multisite Logout Users Safe to Use in 2026?
Generally Safe
Score 85/100Multisite Logout Users has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "multisite-logout-all-users" v1.0.0 plugin demonstrates a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL injection vulnerabilities through prepared statements, and improperly escaped output are significant positive indicators. Furthermore, the lack of file operations and external HTTP requests reduces the potential for common attack vectors. The plugin also exhibits no known CVEs, indicating a clean vulnerability history. However, the complete absence of nonce checks and capability checks is a notable concern. While the static analysis shows no direct entry points that are unprotected, this omission leaves room for potential CSRF attacks or unauthorized access if an administrative function were to be introduced or if the plugin's functionality were to be extended in the future without proper authorization checks. The plugin's current minimal attack surface and clean history are strengths, but the lack of explicit authorization and CSRF protection mechanisms represent a potential weakness that could become exploitable with future modifications or in conjunction with other vulnerabilities.
Key Concerns
- Missing nonce checks
- Missing capability checks
Multisite Logout Users Security Vulnerabilities
Multisite Logout Users Release Timeline
Multisite Logout Users Code Analysis
SQL Query Safety
Multisite Logout Users Attack Surface
WordPress Hooks 2
Maintenance & Trust
Multisite Logout Users Maintenance & Trust
Maintenance Signals
Community Trust
Multisite Logout Users Alternatives
Users Login Monitor
users-login-monitor
A freeware plugin, for daily-notify site administrator, about users who logged in during the day.
Login Logout Redirect – Redirects users after login/logout to a specific URL or page
login-logout-redirect
A simple WordPress plugin that redirects users after login/logout.
Tavakal – Destroy user sessions
tavakal-destroy-user-sessions
Free light plugin to kick out user after being afk, or inactive for long time even if the browser is closed. You can change the time and users roles a …
Admin User Control
admin-user-control
This plugin adds a useful feature to the administration screen that allows administrators to control the users involved in their operations.
User Switching
user-switching
Instant switching between user accounts in WordPress and WooCommerce.
Multisite Logout Users Developer Profile
3 plugins · 150 total installs
How We Detect Multisite Logout Users
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.