FS Registration Password Security & Risk Analysis

wordpress.org/plugins/registration-password

Allow users to set their own password during site registration.

50 active installs v2.0.1 PHP 8.2+ WP 5.9+ Updated Jan 3, 2026
passwordregisterregistrationuser
94
A · Safe
CVEs total1
Unpatched0
Last CVEJan 5, 2026
Safety Verdict

Is FS Registration Password Safe to Use in 2026?

Generally Safe

Score 94/100

FS Registration Password has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Jan 5, 2026Updated 4mo ago
Risk Assessment

The registration-password plugin v2.0.1 exhibits a mixed security posture. On the positive side, the static analysis reveals a commendable lack of immediate code-level risks. There are no identified dangerous functions, all SQL queries utilize prepared statements, and output is consistently escaped. Furthermore, the absence of file operations and external HTTP requests limits potential attack vectors. The presence of a nonce check is a good practice, though the lack of capability checks on entry points is a notable oversight.

The primary concern stems from the vulnerability history. A past critical vulnerability of 'Authorization Bypass Through User-Controlled Key' highlights a significant historical weakness. Although this vulnerability is currently patched, its critical nature and the specific type suggest that the plugin's authorization mechanisms may have been complex or prone to subtle misinterpretations. The fact that this critical vulnerability exists and was patched indicates potential underlying issues in how user-controlled data was handled, even if current code analysis doesn't reveal explicit flaws.

In conclusion, while the current version of the registration-password plugin appears to have addressed immediate code-level vulnerabilities, the historical existence of a critical authorization bypass warrants caution. The lack of capability checks on its entry points is a potential weakness that could be exploited if new vulnerabilities are introduced in future versions. Users should remain vigilant and ensure the plugin is always updated to the latest patched version.

Key Concerns

  • Past critical vulnerability (Authorization Bypass)
  • No capability checks on entry points
Vulnerabilities
1 published

FS Registration Password Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Critical
1

1 total CVE

CVE-2025-15001critical · 9.8Authorization Bypass Through User-Controlled Key

FS Registration Password <= 1.0.1 - Unauthenticated Privilege Escalation via Account Takeover

Jan 5, 2026 Patched in 2.0.1 (1d)
Version History

FS Registration Password Release Timeline

v2.0.1Current
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

FS Registration Password Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Attack Surface

FS Registration Password Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionlogin_enqueue_scriptsinc\namespace.php:12
actionregister_forminc\namespace.php:13
filterregistration_errorsinc\namespace.php:14
filterwp_pre_insert_user_datainc\namespace.php:15
filterwp_new_user_notification_emailinc\namespace.php:16
Maintenance & Trust

FS Registration Password Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 3, 2026
PHP min version8.2
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs50
Developer Profile

FS Registration Password Developer Profile

Firdaus Zahari

4 plugins · 110 total installs

91
trust score
Avg Security Score
87/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect FS Registration Password

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
registration-password/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
user-pass1-wrapwp-pwdpassword-inputhide-if-no-jspw-weakpw-checkboxuser-pass2-wrapindicator-hint
Data Attributes
data-revealdata-pwaria-label
FAQ

Frequently Asked Questions about FS Registration Password