
Multisite User Role Manager Security & Risk Analysis
wordpress.org/plugins/multisite-user-role-managerManage user roles for each blog from a single screen on multisite (WPMU) setups
Is Multisite User Role Manager Safe to Use in 2026?
Generally Safe
Score 85/100Multisite User Role Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "multisite-user-role-manager" plugin v1.0.7 presents a significant security risk due to its large attack surface with unprotected entry points. All seven identified AJAX handlers lack authentication checks, meaning any user, regardless of their permissions, can trigger these actions. While the plugin demonstrates good practices in SQL query handling and output escaping, the absence of capability checks on AJAX actions is a critical oversight. A single high-severity taint flow with an unsanitized path further exacerbates the risk, suggesting potential for path traversal or unintended file access under specific conditions. The plugin's vulnerability history is clean, which is a positive indicator of its development's perceived security, but this is overshadowed by the current lack of essential security measures. The lack of nonce checks on AJAX actions is also a concern, making it susceptible to Cross-Site Request Forgery (CSRF) attacks. Overall, while the plugin uses prepared statements for SQL and mostly escapes output, the unprotected AJAX handlers and the identified taint flow create a substantial security gap that needs immediate attention.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flow with unsanitized path
- Missing capability checks on AJAX
- Missing nonce check on AJAX handlers
Multisite User Role Manager Security Vulnerabilities
Multisite User Role Manager Release Timeline
Multisite User Role Manager Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Multisite User Role Manager Attack Surface
AJAX Handlers 7
WordPress Hooks 13
Maintenance & Trust
Multisite User Role Manager Maintenance & Trust
Maintenance Signals
Community Trust
Multisite User Role Manager Alternatives
Premmerce User Roles
premmerce-user-roles
This plugin has been developed for creating user roles from the WordPress admin area and assigning the arbitrary access rights to them.
Multisite User Management
multisite-user-management
Automatically add users to each site in your WordPress network.
Network User Management
network-user-management
Synchronise users and user roles from main Blog, automatically add users to each site in your WordPress network (Multisite).
WPMU New Blog Default Role
new-blog-default-user-role
Lets site admins specify what role a user who signs up to a new blog will be given by default.
Role Based User Deleter
role-based-user-deleter
Easily delete users based on their roles with Role Based User Deleter. Manage your WordPress users efficiently and securely.
Multisite User Role Manager Developer Profile
3 plugins · 500 total installs
How We Detect Multisite User Role Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/multisite-user-role-manager/css/multisite-user-role-manager-admin.css/wp-content/plugins/multisite-user-role-manager/assets/jqueryui-editable/css/jqueryui-editable.css/wp-content/plugins/multisite-user-role-manager/js/multisite-user-role-manager-admin.js/wp-content/plugins/multisite-user-role-manager/js/multisite-user-role-manager-admin.min.js/wp-content/plugins/multisite-user-role-manager/assets/jqueryui-editable/js/jqueryui-editable.min.js/wp-content/plugins/multisite-user-role-manager/js/multisite-user-role-manager-admin.js/wp-content/plugins/multisite-user-role-manager/js/multisite-user-role-manager-admin.min.jsmultisite-user-role-manager/css/multisite-user-role-manager-admin.css?ver=multisite-user-role-manager/assets/jqueryui-editable/css/jqueryui-editable.css?ver=multisite-user-role-manager/js/multisite-user-role-manager-admin.js?ver=multisite-user-role-manager/js/multisite-user-role-manager-admin.min.js?ver=multisite-user-role-manager/assets/jqueryui-editable/js/jqueryui-editable.min.js?ver=HTML / DOM Fingerprints
wpmuurm-user-roles<!-- Manage user roles for this blog --><!-- Add user to a blog --><!-- User roles for this blog --><!-- User role options -->+2 moredata-user-iddata-blog-idwpmuurm/wp-json/wpmuurm/v1/users//wp-json/wpmuurm/v1/blogs//wp-json/wpmuurm/v1/roles/