
Primary Blog Switcher for SuperAdmins Security & Risk Analysis
wordpress.org/plugins/primary-blog-switcher-for-superadminsWordPress multisite network plugin to allow Network Admin to set the "Primary Blog" (aka Primary Site) of a user while editing a profile.
Is Primary Blog Switcher for SuperAdmins Safe to Use in 2026?
Generally Safe
Score 100/100Primary Blog Switcher for SuperAdmins has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The primary-blog-switcher-for-superadmins plugin v4.6 exhibits a mixed security posture. On the positive side, it has no known historical vulnerabilities (CVEs) and no reported bundled libraries, which often introduce their own security risks. The plugin also utilizes prepared statements for its single SQL query, which is a strong security practice.
However, the static analysis reveals a concerning lack of security controls. The absence of any nonce checks or capability checks across all entry points is a significant weakness. While the attack surface appears small with zero entry points detected, this can be misleading as the taint analysis shows two flows with unsanitized paths. This suggests that even with a limited entry point count, there's a potential for data manipulation or injection if these paths are ever reached through some indirect means or future code modifications. The moderate escaping rate (53%) for outputs also indicates a potential for cross-site scripting (XSS) vulnerabilities.
In conclusion, while the plugin benefits from a clean vulnerability history and good SQL practices, the lack of fundamental security checks like nonces and capability checks, combined with unsanitized taint flows and imperfect output escaping, presents a notable risk. Developers should prioritize implementing proper authentication and authorization for all potential entry points and thoroughly sanitize all output.
Key Concerns
- Missing Nonce Checks
- Missing Capability Checks
- Unsanitized Paths in Taint Flows
- Moderate Output Escaping (53%)
Primary Blog Switcher for SuperAdmins Security Vulnerabilities
Primary Blog Switcher for SuperAdmins Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Primary Blog Switcher for SuperAdmins Attack Surface
WordPress Hooks 3
Maintenance & Trust
Primary Blog Switcher for SuperAdmins Maintenance & Trust
Maintenance Signals
Community Trust
Primary Blog Switcher for SuperAdmins Alternatives
Simple Social Icons
simple-social-icons
This plugin provides two ways to display social icons: a traditional widget (available on all WordPress versions) and block variations for the core So …
Lightweight Social Icons
lightweight-social-icons
Looking to add simple social icons to your widget areas? Choose the size and color of your icons, and then choose from 47 different social profiles.
Socials Ignited
socials-ignited
The Socials Ignited plugin gives you a widget, allowing you to display and link icons on your website of more than 50 social networks.
Unconfirmed
unconfirmed
Allows WordPress admins to manage unactivated users, by activating them manually, deleting their pending registrations, or resending the activation em …
BuddyPress Edit Activity
buddypress-edit-activity
BuddyPress Edit Activity allows your members to edit their activity posts on the front-end of your BuddyPress-powered site.
Primary Blog Switcher for SuperAdmins Developer Profile
4 plugins · 140 total installs
How We Detect Primary Blog Switcher for SuperAdmins
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
update-nagspecial blog add $special_blog_id to add user to some, well, special blog.name="primary_blog"selected="selected"