
Only Admins Security & Risk Analysis
wordpress.org/plugins/only-adminsOnly Admins is a minimal plugin that restricts your entire WordPress site to Admins.
Is Only Admins Safe to Use in 2026?
Generally Safe
Score 100/100Only Admins has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "only-admins" v1.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of any exposed AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code demonstrates excellent security practices with 100% of SQL queries using prepared statements and 100% of output being properly escaped. The presence of at least one capability check is also a positive sign of access control implementation. The taint analysis revealing zero flows with unsanitized paths, particularly at critical and high severity levels, further reinforces the perception of secure coding.
No recorded vulnerabilities, past or present, contribute to a low-risk profile for this plugin. The lack of known CVEs and no history of common vulnerability types suggest that the developers have maintained a secure codebase. While the plugin's limited functionality (implied by the zero entry points) naturally reduces complexity and thus potential vulnerabilities, the observed code signals indicate deliberate security considerations were made. In conclusion, "only-admins" v1.0 appears to be a very secure plugin with no immediate exploitable flaws identified in the static analysis or its vulnerability history. Its strengths lie in its minimal attack surface and adherence to secure coding principles. The only area for potential improvement, though not a current risk, would be to ensure that the single capability check covers all intended administrative functionalities.
Only Admins Security Vulnerabilities
Only Admins Code Analysis
Only Admins Attack Surface
WordPress Hooks 1
Maintenance & Trust
Only Admins Maintenance & Trust
Maintenance Signals
Community Trust
Only Admins Alternatives
Display Environment Type
display-environment-type
Displays WordPress 5.5's environment type setting in the admin bar and the "At a Glance" dashboard widget.
WP Secure Maintenance
wp-secure-maintainance
Want to lock your site for Maintenance or Development? Then this is the right Plugin
WP Shield
wp-shield
This plugin will allow you to secure your development, staging and UAT environments with an http authentication block that can be controlled in admin …
The Permalinker
the-permalinker
Use short codes to dynamically link to your WordPress pages and posts. All you need is the ID. This can come in handy when developing content for Word …
Dev Theme
dev-theme
DEV Theme
Only Admins Developer Profile
1 plugin · 10 total installs
How We Detect Only Admins
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
You don't have permission to accesss this page. <a href="%s">Logout?</a>