
Multisite New User Form Security & Risk Analysis
wordpress.org/plugins/multisite-new-user-formThis plugin allows you to create users with custom password on multisite website.
Is Multisite New User Form Safe to Use in 2026?
Generally Safe
Score 85/100Multisite New User Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The multisite-new-user-form v1.0 plugin exhibits a generally strong security posture based on the provided static analysis. There are no identified vulnerabilities in its attack surface, such as AJAX handlers, REST API routes, shortcodes, or cron events, that lack proper authentication or permission checks. Furthermore, the code demonstrates good practices by exclusively using prepared statements for SQL queries, properly escaping all output, and implementing nonce and capability checks. The absence of file operations and external HTTP requests also reduces potential attack vectors.
However, a significant concern is the presence of the `unserialize` function. While not directly flagged as a vulnerability in the static analysis or taint analysis (which found no unsanitized flows), the use of `unserialize` with untrusted input is a well-known risk that can lead to remote code execution if the input is manipulated. The lack of vulnerability history for this plugin is positive, suggesting a history of secure development or limited exposure, but it does not negate the inherent risk associated with `unserialize`.
In conclusion, the plugin has many strengths, particularly in its handling of common web vulnerabilities. The primary weakness lies in the potential risk posed by the `unserialize` function, which, despite the absence of exploitable taint flows in this analysis, warrants caution and potential mitigation through careful input validation before deserialization.
Key Concerns
- Presence of unserialize function
Multisite New User Form Security Vulnerabilities
Multisite New User Form Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Multisite New User Form Attack Surface
WordPress Hooks 3
Maintenance & Trust
Multisite New User Form Maintenance & Trust
Maintenance Signals
Community Trust
Multisite New User Form Alternatives
Create User With Password Multisite
create-user-with-password-multisite
Allow website administrators to allocate passwords to users as they add them to invidivual sites in WordPress Multisite.
Network Subsite User Registration
network-subsite-user-registration
Allow the public to register user accounts on Subsites within a Network (MultiSite) installation.
WP Notifications Manager
wp-notifications-manager
Manage new user registration & password change notifications.
MultiSite New User, No Confirmation
multisite-new-user-no-confirmation
Mimic the super-admin "Skip Confirmation Email" checkbox for regular users.
Network Blog Manager
network-blog-manager
A simple but powerful blog manager to be used in blog networks. Include an internal search engine, statistics, and some useful tool.
Multisite New User Form Developer Profile
2 plugins · 10 total installs
How We Detect Multisite New User Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
custom-fieldswp-pwdpassword-input-wrapper<!-- #24364 workaround -->data-revealdata-pw