
Simple User Listing Security & Risk Analysis
wordpress.org/plugins/simple-user-listingA shortcode for displaying paginated lists of users.
Is Simple User Listing Safe to Use in 2026?
Generally Safe
Score 92/100Simple User Listing has a strong security track record. Known vulnerabilities have been patched promptly.
The security posture of the 'simple-user-listing' plugin v2.0.4 appears to be generally good, with a limited attack surface and strong practices in output escaping and the use of prepared statements for SQL queries. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its positive security profile. Taint analysis also revealed no critical or high severity issues.
However, there are areas for improvement. The plugin lacks nonce checks on any of its entry points, which is a significant oversight for a WordPress plugin. While there are no currently unpatched vulnerabilities, the history includes one medium severity Cross-Site Scripting (XSS) vulnerability discovered relatively recently. This suggests that while past issues have been addressed, the potential for input validation and sanitization weaknesses exists.
In conclusion, 'simple-user-listing' v2.0.4 demonstrates several good security practices, particularly in code execution and data handling. The primary concerns are the complete absence of nonce checks and the historical presence of an XSS vulnerability. These factors necessitate careful consideration, although the overall risk is likely moderate due to the limited attack surface and good handling of SQL and output.
Key Concerns
- Missing nonce checks on entry points
- Past medium XSS vulnerability
Simple User Listing Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Simple User Listing <= 1.9.2 - Reflected Cross-Site Scripting via as
Simple User Listing Code Analysis
SQL Query Safety
Output Escaping
Simple User Listing Attack Surface
REST API Routes 1
Shortcodes 1
WordPress Hooks 29
Maintenance & Trust
Simple User Listing Maintenance & Trust
Maintenance Signals
Community Trust
Simple User Listing Alternatives
Co-Authors Plus
co-authors-plus
Assign multiple bylines to posts, pages, and custom post types with a search-as-you-type input box.
AyeCode Connect
ayecode-connect
Use this service plugin to easily activate any of our products, open a support ticket and view documentation all from your wp-admin!
Starbox – the Author Box for Humans
starbox
Starbox is the Author Box for Humans. Professional Themes to choose from, HTML5, Social Media Profiles, Google Authorship
BP Profile Search
bp-profile-search
Member search and member directories for BuddyPress and the BuddyBoss Platform.
Smart User Slug Hider
smart-user-slug-hider
Hide usernames in Author Pages URLs to enhance Security
Simple User Listing Developer Profile
6 plugins · 99K total installs
How We Detect Simple User Listing
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-user-listing/assets/css/simple-user-listing.css/wp-content/plugins/simple-user-listing/assets/js/simple-user-listing.js/wp-content/plugins/simple-user-listing/dist/directory/style-index.css/wp-content/plugins/simple-user-listing/dist/directory/index.js/wp-content/plugins/simple-user-listing/assets/js/simple-user-listing.js/wp-content/plugins/simple-user-listing/dist/directory/index.jssimple-user-listing/assets/css/simple-user-listing.css?ver=simple-user-listing/assets/js/simple-user-listing.js?ver=simple-user-listing/dist/directory/style-index.css?ver=simple-user-listing/dist/directory/index.js?ver=HTML / DOM Fingerprints
simple-user-listingsul-users-listsul-user-profile<!-- Simple User Listing --><!-- End Simple User Listing -->data-simple-user-listingdata-sul-query-iddata-sul-roledata-sul-numbersimpleUserListing/wp-json/simple-user-listing/v1/user-roles<div class="simple-user-listing"><ul class="sul-users-list"><li class="sul-user-profile">