
Smart User Slug Hider Security & Risk Analysis
wordpress.org/plugins/smart-user-slug-hiderHide usernames in Author Pages URLs to enhance Security
Is Smart User Slug Hider Safe to Use in 2026?
Generally Safe
Score 85/100Smart User Slug Hider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "smart-user-slug-hider" v4.0.6 plugin exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests is a positive indicator. Furthermore, all SQL queries are properly prepared, and there are no recorded vulnerabilities or CVEs, suggesting a mature and well-maintained codebase. The presence of nonce and capability checks on two entry points demonstrates an awareness of basic security practices.
However, a significant concern lies in the output escaping. With 39 total outputs and only 8% properly escaped, this indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed without proper sanitization or encoding is a potential vector for attackers to inject malicious scripts. While the attack surface is small (3 shortcodes) and none are currently unprotected, the inadequate output escaping is a critical weakness that overshadows the otherwise positive findings.
In conclusion, the plugin has a solid foundation with no known exploitable vulnerabilities and good practices in SQL handling and authentication checks. However, the widespread lack of proper output escaping creates a significant and readily exploitable security risk. Addressing the output escaping issues should be the absolute priority to improve the plugin's security.
Key Concerns
- Low output escaping percentage
Smart User Slug Hider Security Vulnerabilities
Smart User Slug Hider Release Timeline
Smart User Slug Hider Code Analysis
Output Escaping
Smart User Slug Hider Attack Surface
Shortcodes 3
WordPress Hooks 13
Maintenance & Trust
Smart User Slug Hider Maintenance & Trust
Maintenance Signals
Community Trust
Smart User Slug Hider Alternatives
Co-Authors Plus
co-authors-plus
Assign multiple bylines to posts, pages, and custom post types with a search-as-you-type input box.
Starbox – the Author Box for Humans
starbox
Starbox is the Author Box for Humans. Professional Themes to choose from, HTML5, Social Media Profiles, Google Authorship
Simple User Listing
simple-user-listing
A shortcode for displaying paginated lists of users.
Smart Custom Display Name
smart-custom-display-name
Allows you to change the value of "Display name publicly as" in user profiles to any string
Team List
wp-team-list
Display your teammates anywhere on your WordPress site using this easy-to-use plugin.
Smart User Slug Hider Developer Profile
7 plugins · 13K total installs
How We Detect Smart User Slug Hider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smart-user-slug-hider/assets/css/admin.css/wp-content/plugins/smart-user-slug-hider/assets/js/admin.js/wp-content/plugins/smart-user-slug-hider/assets/js/admin.jssmart-user-slug-hider/assets/css/admin.css?ver=smart-user-slug-hider/assets/js/admin.js?ver=HTML / DOM Fingerprints
toggleslidercaptionname="smart-user-slug-hider-hide_usernames"id="smart-user-slug-hider-hide_usernames"name="smart-user-slug-hider-custom_text"id="smart-user-slug-hider-custom_text"name="smart-user-slug-hider-exclude_users"id="smart-user-slug-hider-exclude_users"