
Permanent User Password Security & Risk Analysis
wordpress.org/plugins/permanent-user-passwordA light-weight WordPress plugin that empowers administrators to set permanent passwords for users on their websites.
Is Permanent User Password Safe to Use in 2026?
Generally Safe
Score 100/100Permanent User Password has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "permanent-user-password" plugin v1.0.1 demonstrates a strong security posture based on the provided static analysis. The code shows no dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. Furthermore, there are no file operations or external HTTP requests, which significantly reduces the attack surface. The absence of known vulnerabilities and CVEs in its history is also a positive indicator of its current security, suggesting a history of responsible development and maintenance.
However, a key concern arises from the complete lack of nonce checks and capability checks. While the attack surface is currently minimal (0 AJAX, 0 REST API, 0 shortcodes), any future addition of such entry points without proper authentication and authorization mechanisms would introduce significant security risks. The presence of a cron event also warrants attention; its functionality and whether it performs any sensitive operations that might be exploitable without proper checks should be investigated.
In conclusion, the plugin is currently in a good state, with strong coding practices observed in SQL and output handling. The absence of vulnerabilities is reassuring. The primary area for improvement and potential risk lies in the complete reliance on the absence of exposed entry points rather than implementing robust built-in security checks like nonces and capability checks, which would make it more resilient against future development changes or unforeseen attack vectors.
Key Concerns
- No nonce checks implemented
- No capability checks implemented
Permanent User Password Security Vulnerabilities
Permanent User Password Code Analysis
Output Escaping
Permanent User Password Attack Surface
WordPress Hooks 7
Scheduled Events 1
Maintenance & Trust
Permanent User Password Maintenance & Trust
Maintenance Signals
Community Trust
Permanent User Password Alternatives
Admin Notify
admin-notify
Short Description: Admin Notify sends email notifications when administrator accounts are added, updated, or deleted.
Solid Security – Password, Two Factor Authentication, and Brute Force Protection
better-wp-security
Harden your site security with Login Security, Two-Factor Authentication (2FA), Vulnerability Scanner, Firewall, and more. Formerly iThemes Security.
Protect Uploads
protect-uploads
Protect your uploads directory. Prevent browsing, add watermarks, disable right-click, and password-protect files. For more information, visit protect …
Google Authenticator
google-authenticator
Google Authenticator for your WordPress blog.
Password Strength Settings for WooCommerce
wc-password-strength-settings
Help secure your WooCommerce site by enforcing stronger passwords and taking additional control of your strength requirements.
Permanent User Password Developer Profile
3 plugins · 2K total installs
How We Detect Permanent User Password
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
name="pupa_check"id="pupa_check"name="pupa_password"id="pupa_password"for="pupa_check"for="pupa_password"