WP Online Active Users Security & Risk Analysis

wordpress.org/plugins/online-active-users

WP Online Active Users is a lightweight, powerful plugin to monitor and display how many users are currently online active on your WordPress website.

2K active installs v3.1 PHP 7.3+ WP 6.3+ Updated Dec 22, 2025
active-usersonline-usersuser-statuswoocommerce-userswp-online-users
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Online Active Users Safe to Use in 2026?

Generally Safe

Score 100/100

WP Online Active Users has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The online-active-users plugin v3.1 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean taint analysis suggest a low risk of severe, pre-existing vulnerabilities. The plugin also demonstrates good practices by utilizing prepared statements for all SQL queries and avoiding dangerous functions and file operations. However, there are areas for improvement that introduce potential, albeit currently unexploited, risks.

The primary concerns stem from the lack of capability checks and nonce verification across its entry points. While the attack surface is small (one shortcode), the absence of these security mechanisms means that any user, regardless of their role, could potentially trigger the shortcode's functionality. This is further compounded by the fact that 33% of output is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if malicious data is injected and then rendered without sanitization.

Overall, the plugin appears to be developed with some security awareness, particularly in its handling of database interactions and its limited attack surface. However, the lack of robust authorization and output sanitization creates a potential for vulnerabilities to be introduced or exploited in the future. The absence of past vulnerabilities is a positive sign, but it doesn't negate the risks presented by the current code analysis.

Key Concerns

  • Missing capability checks
  • Missing nonce checks
  • Unescaped output detected
Vulnerabilities
None known

WP Online Active Users Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Online Active Users Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
20 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

67% escaped30 total outputs
Attack Surface

WP Online Active Users Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[webi_active_user] inc\webi-functions.php:91
WordPress Hooks 15
actioninitonline-active-users.php:44
actioninitonline-active-users.php:45
actionclear_auth_cookieonline-active-users.php:46
actionwp_loadedonline-active-users.php:47
actionadmin_enqueue_scriptsonline-active-users.php:48
actionadmin_initonline-active-users.php:49
actionwp_dashboard_setuponline-active-users.php:50
filtermanage_users_columnsonline-active-users.php:51
actionmanage_users_custom_columnonline-active-users.php:52
filterviews_usersonline-active-users.php:53
actionadmin_bar_menuonline-active-users.php:54
filterplugin_row_metaonline-active-users.php:55
actionadmin_menuonline-active-users.php:56
actionadmin_noticesonline-active-users.php:58
actionwidgets_initonline-active-users.php:255
Maintenance & Trust

WP Online Active Users Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 22, 2025
PHP min version7.3
Downloads22K

Community Trust

Rating94/100
Number of ratings38
Active installs2K
Developer Profile

WP Online Active Users Developer Profile

Nikul Patel

2 plugins · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Online Active Users

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/online-active-users/assets/css/style.css
Script Paths
/wp-content/plugins/online-active-users/assets/js/custom.js
Version Parameters
online-active-users/assets/js/custom.js?ver=

HTML / DOM Fingerprints

CSS Classes
webizito-last-seen
Data Attributes
data-timestamp
FAQ

Frequently Asked Questions about WP Online Active Users