Stop User Enumeration Security & Risk Analysis

wordpress.org/plugins/stop-user-enumeration

Helps secure your site against hacking attacks through detecting User Enumeration

50K active installs v1.7.7 PHP 7.4+ WP 6.3+ Updated Dec 15, 2025
fail2bansecurityuser-enumerationwpscan
91
A · Safe
CVEs total6
Unpatched0
Last CVEJun 26, 2025
Safety Verdict

Is Stop User Enumeration Safe to Use in 2026?

Generally Safe

Score 91/100

Stop User Enumeration has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

6 known CVEsLast CVE: Jun 26, 2025Updated 5mo ago
Risk Assessment

The "stop-user-enumeration" plugin v1.7.7 exhibits a mixed security posture. While static analysis reveals a commendably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or proper permission checks, and all SQL queries utilize prepared statements, there are significant historical concerns.

The plugin has a history of 6 known Common Vulnerabilities and Exposures (CVEs), with 2 high and 4 medium severity vulnerabilities. The types of past vulnerabilities, including Protection Mechanism Failure, Missing Authorization, Exposure of Sensitive Information, Cross-Site Scripting, and Improper Access Control, suggest recurring issues in how the plugin handles user access and input validation. The most recent vulnerability was identified on 2025-06-26, indicating ongoing security challenges. The absence of taint analysis data and the zero count for dangerous functions, file operations, and external HTTP requests in the static analysis are positive signs, but they do not fully mitigate the risk presented by the historical vulnerability patterns.

In conclusion, the current version of the plugin appears to have addressed immediate code-level risks in its entry points and database interactions based on static analysis. However, the substantial historical vulnerability record, particularly the high and medium severity issues involving authorization, access control, and information exposure, necessitates a cautious approach. The plugin's security is weakened by its past, and it is crucial for users to ensure they are running the absolute latest version, as the last known vulnerability is surprisingly recent and implies potential for future undiscovered or re-emerging issues.

Key Concerns

  • Total known CVEs: 6
  • High severity CVEs: 2
  • Medium severity CVEs: 4
  • Last vulnerability: 2025-06-26
  • Missing Nonce Checks (0/0)
  • Missing Capability Checks (0/0)
  • Unsanitized Output (6% unescaped)
Vulnerabilities
6 published

Stop User Enumeration Security Vulnerabilities

CVEs by Year

1 CVE in 2014
2014
3 CVEs in 2017
2017
1 CVE in 2019
2019
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
2
Medium
4

6 total CVEs

CVE-2025-4302medium · 5.3Protection Mechanism Failure

Stop User Enumeration <= 1.7.2 - Protection Mechanism Bypass

Jun 26, 2025 Patched in 1.7.3 (30d)

Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update

Feb 25, 2019 Patched in 1.3.20 (1793d)
CVE-2017-1000226medium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

Stop User Enumeration plugin <1.3.9 - User Enumeration

May 16, 2017 Patched in 1.3.9 (2443d)
CVE-2017-18536medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Stop User Enumeration <= 1.3.7 - Cross-Site Scripting

Jan 15, 2017 Patched in 1.3.8 (2564d)
WF-e7d4830b-f60a-4556-b40f-1bf9d5a296ad-stop-user-enumerationmedium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

Stop User Enumeration <= 1.3.4 - Username Enumeration Bypasses

Jan 4, 2017 Patched in 1.3.5 (2575d)

Stop User Enumeration <= 1.2.4 - Security Bypass

Feb 3, 2014 Patched in 1.2.5 (3641d)
Version History

Stop User Enumeration Release Timeline

v1.7.7Current
v1.7.6
v1.7.5
v1.7.4
v1.7.3
v1.7.21 CVE
v1.7.11 CVE
v1.71 CVE
v1.6.31 CVE
v1.6.21 CVE
v1.6.11 CVE
v1.61 CVE
v1.5.11 CVE
v1.5.01 CVE
v1.4.91 CVE
v1.4.81 CVE
v1.4.71 CVE
v1.4.61 CVE
v1.4.51 CVE
v1.4.41 CVE
Code Analysis
Analyzed Mar 16, 2026

Stop User Enumeration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
13 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped14 total outputs
Attack Surface

Stop User Enumeration Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_enqueue_scriptsadmin\class-admin-pages.php:43
filterscreen_layout_columnsadmin\class-admin-pages.php:46
actionadmin_menuincludes\class-core.php:114
actionwp_enqueue_scriptsincludes\class-core.php:154
actioninitincludes\class-core.php:157
filterrest_pre_dispatchincludes\class-core.php:158
filterwp_sitemaps_add_providerincludes\class-core.php:160
filteroembed_response_dataincludes\class-core.php:163
Maintenance & Trust

Stop User Enumeration Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 15, 2025
PHP min version7.4
Downloads1.3M

Community Trust

Rating98/100
Number of ratings130
Active installs50K
Developer Profile

Stop User Enumeration Developer Profile

fullworks

13 plugins · 79K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
1299 days
View full developer profile
Detection Fingerprints

How We Detect Stop User Enumeration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/stop-user-enumeration/admin/css/admin-style.css/wp-content/plugins/stop-user-enumeration/admin/js/admin-script.js
Script Paths
/wp-content/plugins/stop-user-enumeration/admin/js/admin-script.js
Version Parameters
stop-user-enumeration/admin/css/admin-style.css?ver=stop-user-enumeration/admin/js/admin-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
fs-settings-meta-box-wrap
HTML Comments
<![CDATA[//]]>// @TODO think about local script
Data Attributes
id="fs-smb-form"id="fx-smb-form"
JS Globals
window.jQueryjQuery
FAQ

Frequently Asked Questions about Stop User Enumeration