
Smart Custom Display Name Security & Risk Analysis
wordpress.org/plugins/smart-custom-display-nameAllows you to change the value of "Display name publicly as" in user profiles to any string
Is Smart Custom Display Name Safe to Use in 2026?
Generally Safe
Score 92/100Smart Custom Display Name has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the "smart-custom-display-name" v5.0.3 plugin appears to be strong based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code analysis shows no dangerous functions, no raw SQL queries (100% using prepared statements), no file operations, and no external HTTP requests. The presence of nonce and capability checks, albeit minimal, is a positive sign. The vulnerability history is also clean, with no recorded CVEs, which suggests a well-maintained or less complex plugin.
However, a significant concern is the extremely low percentage of properly escaped output (3%). With 37 total outputs analyzed and only 3% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed on the frontend or backend without proper sanitization and escaping could be exploited by attackers to inject malicious scripts. While taint analysis did not reveal specific flows, the general lack of output escaping is a critical weakness that requires immediate attention. The plugin's strengths lie in its limited attack surface and secure database interactions, but the widespread lack of output escaping presents a substantial risk.
Key Concerns
- Low output escaping (3%)
- Limited security checks (2 nonce, 2 capability)
Smart Custom Display Name Security Vulnerabilities
Smart Custom Display Name Code Analysis
Output Escaping
Smart Custom Display Name Attack Surface
WordPress Hooks 9
Maintenance & Trust
Smart Custom Display Name Maintenance & Trust
Maintenance Signals
Community Trust
Smart Custom Display Name Alternatives
Co-Authors Plus
co-authors-plus
Assign multiple bylines to posts, pages, and custom post types with a search-as-you-type input box.
Starbox – the Author Box for Humans
starbox
Starbox is the Author Box for Humans. Professional Themes to choose from, HTML5, Social Media Profiles, Google Authorship
Smart User Slug Hider
smart-user-slug-hider
Hide usernames in Author Pages URLs to enhance Security
Simple User Listing
simple-user-listing
A shortcode for displaying paginated lists of users.
Team List
wp-team-list
Display your teammates anywhere on your WordPress site using this easy-to-use plugin.
Smart Custom Display Name Developer Profile
7 plugins · 13K total installs
How We Detect Smart Custom Display Name
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smart-custom-display-name/css/smart-custom-display-name.css/wp-content/plugins/smart-custom-display-name/js/smart-custom-display-name.js/wp-content/plugins/smart-custom-display-name/js/smart-custom-display-name.jssmart-custom-display-name/css/smart-custom-display-name.css?ver=smart-custom-display-name/js/smart-custom-display-name.js?ver=HTML / DOM Fingerprints
toggleslidercheckname="smart-custom-display-name-user_display_name"id="smart-custom-display-name-user_display_name"name="smart-custom-display-name-remove_display_name"id="smart-custom-display-name-remove_display_name"