
Require First and Last Name Security & Risk Analysis
wordpress.org/plugins/require-first-and-last-nameRequire first and last name from users who are editing their profiles.
Is Require First and Last Name Safe to Use in 2026?
Generally Safe
Score 85/100Require First and Last Name has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "require-first-and-last-name" v1.2 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code analysis reveals no dangerous function usage, no file operations, no external HTTP requests, and a complete absence of taint analysis findings, indicating a clean codebase in these critical areas.
However, a notable concern arises from the "Output escaping" signal, which indicates that 100% of outputs are not properly escaped. This represents a potential cross-site scripting (XSS) vulnerability, as user-supplied data or plugin-generated content could be rendered directly in the browser without sanitization, allowing for malicious script injection. The lack of any capability checks or nonce checks, while not directly creating an immediate threat given the limited attack surface, does mean that any future expansion of the plugin's functionality could inherit these weaknesses without proper security considerations.
The vulnerability history is completely clean, with no known CVEs. This, combined with the static analysis findings, suggests that the developers have a good understanding of secure coding practices, with the exception of output escaping. The overall security posture is strong due to the minimal attack surface and absence of critical code-level vulnerabilities, but the unescaped output presents a clear and addressable risk.
Key Concerns
- 100% of outputs not properly escaped
Require First and Last Name Security Vulnerabilities
Require First and Last Name Code Analysis
Output Escaping
Require First and Last Name Attack Surface
WordPress Hooks 2
Maintenance & Trust
Require First and Last Name Maintenance & Trust
Maintenance Signals
Community Trust
Require First and Last Name Alternatives
Quick User Profile Update
wp-quick-username-update
Quick User Profile Update will give admin authority of user profile quick update from admin panel
Edit Usernames
edit-usernames
The Edit Usernames plugin allows WordPress admins and WooCommerce managers to edit the users' usernames through the admin dashboard. Simple!
One User Avatar | User Profile Picture
one-user-avatar
Use any image from your WordPress Media Library as a custom user avatar or user profile picture. Add your own Default Avatar.
Simple Local Avatars
simple-local-avatars
Adds an avatar upload field to user profiles. Generates requested sizes on demand just like Gravatar!
User Profile Picture
metronet-profile-picture
Set a custom profile image (avatar) for a user using the standard WordPress media upload tool.
Require First and Last Name Developer Profile
13 plugins · 6K total installs
How We Detect Require First and Last Name
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
descriptionrequired