Show user avatar Security & Risk Analysis

wordpress.org/plugins/show-user-avatar

Add the shortcode [avatar] in the Header, footer ore on any post and page. With this plugin you can display the logged in user avatar.

10 active installs v1.0 PHP 8.0+ WP 6.9+ Updated Jan 9, 2026
show-user-avatar
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Show user avatar Safe to Use in 2026?

Generally Safe

Score 100/100

Show user avatar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "show-user-avatar" plugin v1.0 exhibits a generally positive security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and unescaped output are significant strengths. Furthermore, the lack of file operations and external HTTP requests reduces the potential for common attack vectors. The plugin also appears to have a limited attack surface, with only one shortcode and no identified AJAX handlers or REST API routes that are not protected by authentication. The vulnerability history is also clean, with no recorded CVEs, which suggests a history of secure development or successful patching. However, a key concern is the complete lack of nonce checks and capability checks. While the current entry points are limited and appear to be protected implicitly, this absence represents a potential weakness. If new functionality is added or existing functionality evolves to handle user-supplied data in ways not currently apparent, the lack of nonces and capability checks could lead to privilege escalation or cross-site request forgery vulnerabilities. This is a critical area for improvement to ensure long-term security resilience.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Show user avatar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Show user avatar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Attack Surface

Show user avatar Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[avatar] Show user avatar.php:18
Maintenance & Trust

Show user avatar Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 9, 2026
PHP min version8.0
Downloads941

Community Trust

Rating100/100
Number of ratings2
Active installs10
Alternatives

Show user avatar Alternatives

No alternatives data available yet.

Developer Profile

Show user avatar Developer Profile

Benjamin Hagh Parast

18 plugins · 330 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Show user avatar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Show user avatar