
NutsForPress Restricted Contents Security & Risk Analysis
wordpress.org/plugins/nutsforpress-restricted-contentsNutsForPress Restricted Contents allows you to restrict pages, posts and media (images, zip files, pdf) to logged in users only.
Is NutsForPress Restricted Contents Safe to Use in 2026?
Generally Safe
Score 100/100NutsForPress Restricted Contents has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "nutsforpress-restricted-contents" plugin v1.4 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping a high percentage of its output. The plugin also correctly implements nonce and capability checks for most of its functionality. However, a significant concern arises from the presence of an unprotected AJAX handler. This direct entry point into the plugin's functionality, without any authentication or authorization checks, presents a clear attack vector. Furthermore, the taint analysis reveals two high-severity flows with unsanitized paths, suggesting potential vulnerabilities that could be exploited through the unprotected AJAX handler.
The plugin's vulnerability history is a strong positive indicator, with no known CVEs ever recorded. This suggests a generally well-developed and maintained codebase. Despite the absence of past vulnerabilities, the current static analysis reveals critical areas for improvement. The single unprotected AJAX handler and the high-severity taint flows are the primary risks that need immediate attention to ensure the plugin's continued security.
Key Concerns
- Unprotected AJAX handler
- High severity taint flow (2 instances)
NutsForPress Restricted Contents Security Vulnerabilities
NutsForPress Restricted Contents Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
NutsForPress Restricted Contents Attack Surface
AJAX Handlers 1
WordPress Hooks 14
Maintenance & Trust
NutsForPress Restricted Contents Maintenance & Trust
Maintenance Signals
Community Trust
NutsForPress Restricted Contents Alternatives
Force Login
wp-force-login
Force Login is a simple lightweight plugin that requires visitors to log in to interact with the website.
BuddyPress Members Only
buddypress-members-only
BuddyPress Members Only restricts Your Buddypress and Wordpress to logged in/registered members.
RIACO Content Protector
riaco-content-protector
Protect any portion of your WordPress content using a simple shortcode. Includes global password, AJAX unlock, and site-wide instant access.
BuddyPress Members Only
ssl-for-buddypress
BuddyPress Members Only restricts Your Buddypress and Wordpress to logged in/registered members.
Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content
password-protected
Protect your WordPress site, pages, posts, WooCommerce products, and categories with single or multiple passwords.
NutsForPress Restricted Contents Developer Profile
9 plugins · 460 total installs
How We Detect NutsForPress Restricted Contents
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nutsforpress-restricted-contents/css/nfproot-style.css/wp-content/plugins/nutsforpress-restricted-contents/js/nfproot-script.js/wp-content/plugins/nutsforpress-restricted-contents/js/nfproot-save-settings.js/wp-content/plugins/nutsforpress-restricted-contents/js/nfproot-script.js/wp-content/plugins/nutsforpress-restricted-contents/js/nfproot-save-settings.jsHTML / DOM Fingerprints
dashicons-privacytitle="Restricted by NutsForPress Restricted Contents"alt="Restricted by NutsForPress Restricted Contents"nfproot_save_settings_object