
Smart User Slug Hider Security & Risk Analysis
wordpress.org/plugins/smart-user-slug-hiderHide usernames in Author Pages URLs to enhance Security
Is Smart User Slug Hider Safe to Use in 2026?
Generally Safe
Score 92/100Smart User Slug Hider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "smart-user-slug-hider" v4.0.6 plugin exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests is a positive indicator. Furthermore, all SQL queries are properly prepared, and there are no recorded vulnerabilities or CVEs, suggesting a mature and well-maintained codebase. The presence of nonce and capability checks on two entry points demonstrates an awareness of basic security practices.
However, a significant concern lies in the output escaping. With 39 total outputs and only 8% properly escaped, this indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed without proper sanitization or encoding is a potential vector for attackers to inject malicious scripts. While the attack surface is small (3 shortcodes) and none are currently unprotected, the inadequate output escaping is a critical weakness that overshadows the otherwise positive findings.
In conclusion, the plugin has a solid foundation with no known exploitable vulnerabilities and good practices in SQL handling and authentication checks. However, the widespread lack of proper output escaping creates a significant and readily exploitable security risk. Addressing the output escaping issues should be the absolute priority to improve the plugin's security.
Key Concerns
- Low output escaping percentage
Smart User Slug Hider Security Vulnerabilities
Smart User Slug Hider Code Analysis
Output Escaping
Smart User Slug Hider Attack Surface
Shortcodes 3
WordPress Hooks 13
Maintenance & Trust
Smart User Slug Hider Maintenance & Trust
Maintenance Signals
Community Trust
Smart User Slug Hider Alternatives
Co-Authors Plus
co-authors-plus
Assign multiple bylines to posts, pages, and custom post types with a search-as-you-type input box.
Starbox – the Author Box for Humans
starbox
Starbox is the Author Box for Humans. Professional Themes to choose from, HTML5, Social Media Profiles, Google Authorship
Simple User Listing
simple-user-listing
A shortcode for displaying paginated lists of users.
Smart Custom Display Name
smart-custom-display-name
Allows you to change the value of "Display name publicly as" in user profiles to any string
Team List
wp-team-list
Display your teammates anywhere on your WordPress site using this easy-to-use plugin.
Smart User Slug Hider Developer Profile
7 plugins · 13K total installs
How We Detect Smart User Slug Hider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smart-user-slug-hider/assets/css/admin.css/wp-content/plugins/smart-user-slug-hider/assets/js/admin.js/wp-content/plugins/smart-user-slug-hider/assets/js/admin.jssmart-user-slug-hider/assets/css/admin.css?ver=smart-user-slug-hider/assets/js/admin.js?ver=HTML / DOM Fingerprints
toggleslidercaptionname="smart-user-slug-hider-hide_usernames"id="smart-user-slug-hider-hide_usernames"name="smart-user-slug-hider-custom_text"id="smart-user-slug-hider-custom_text"name="smart-user-slug-hider-exclude_users"id="smart-user-slug-hider-exclude_users"