Readministrator (Read Only Administrator) Security & Risk Analysis

wordpress.org/plugins/readministrator-read-only-administrator

Allowing users to see the admin settings page. Just Seeing, No edit allowed :) These users will have all the privilege of editors along with that they …

10 active installs v0.0.1 PHP + WP 4.4+ Updated Jan 9, 2021
adminadministratoroptionsread-onlysettings
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Readministrator (Read Only Administrator) Safe to Use in 2026?

Generally Safe

Score 85/100

Readministrator (Read Only Administrator) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "readministrator-read-only-administrator" plugin v0.0.1 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, external HTTP requests, file operations, and the exclusive use of prepared statements for SQL queries are all positive indicators. Furthermore, the comprehensive output escaping and the lack of any recorded vulnerabilities in its history suggest a commitment to secure coding practices or simply a very limited exposure to testing and exploitation, which is common for early versions.

However, the most significant concern arises from the complete absence of nonce checks and capability checks. This means that any functionality exposed by this plugin, even if not immediately apparent as an entry point (like AJAX or REST API), could potentially be triggered by any authenticated user, or even unauthenticated users if these checks are missing at a higher WordPress level. While the static analysis reports zero unprotected entry points, the lack of capability checks is a critical omission that bypasses WordPress's built-in permission system and could lead to privilege escalation or unauthorized actions if any functionality is added or modified in future versions, or if hidden entry points exist.

In conclusion, while the current version demonstrates good practices in areas like SQL and output handling, the critical lack of capability and nonce checks represents a substantial security weakness. The absence of vulnerability history is a good sign but does not negate the identified coding practice concerns. A balanced view is that the plugin is clean in its current, presumably minimal, implementation, but it carries a high risk due to the fundamental security controls that are missing.

Key Concerns

  • Missing capability checks
  • Missing nonce checks
Vulnerabilities
None known

Readministrator (Read Only Administrator) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Readministrator (Read Only Administrator) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Readministrator (Read Only Administrator) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninitwp-readministrator.php:49
actioninitwp-readministrator.php:57
filteradmin_body_classwp-readministrator.php:73
actionadmin_noticeswp-readministrator.php:112
filterpre_update_optionwp-readministrator.php:138
Maintenance & Trust

Readministrator (Read Only Administrator) Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedJan 9, 2021
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Readministrator (Read Only Administrator) Developer Profile

Dhanendran Rajagopal

4 plugins · 2K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
92 days
View full developer profile
Detection Fingerprints

How We Detect Readministrator (Read Only Administrator)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/readministrator-read-only-administrator/style.css
Version Parameters
readministrator-read-only-administrator/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
readministrator
Shortcode Output
You can only able to see the settings and can't make any changes.
FAQ

Frequently Asked Questions about Readministrator (Read Only Administrator)