
Support Me Security & Risk Analysis
wordpress.org/plugins/support-meAllows you to generate expireable user accounts for support purposes.
Is Support Me Safe to Use in 2026?
Generally Safe
Score 85/100Support Me has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "support-me" plugin v1.0.6 exhibits a generally strong security posture based on the static analysis. The plugin demonstrates good security practices by implementing nonce checks and capability checks on its entry points, specifically its AJAX handler. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests, coupled with the exclusive use of prepared statements for SQL queries, significantly reduces the risk of common vulnerabilities. The high percentage of properly escaped output is also a positive indicator of secure coding.
Despite the positive aspects, there are minor areas for improvement. The static analysis did not reveal any taint flows, which is excellent, but it's important to note that taint analysis can be limited by its scope. The lack of any recorded vulnerability history is a strong positive, suggesting the plugin has a history of being well-maintained and secure. However, it's crucial to remember that past security does not guarantee future security, and ongoing vigilance is always necessary.
In conclusion, "support-me" v1.0.6 appears to be a securely developed plugin with a minimal attack surface and robust security measures in place. The absence of critical vulnerabilities in static analysis and historical data is highly reassuring. The primary recommendation would be to continue this diligent approach to security, ensuring all new code adheres to these secure coding standards.
Key Concerns
- Unescaped output detected
Support Me Security Vulnerabilities
Support Me Release Timeline
Support Me Code Analysis
Output Escaping
Support Me Attack Surface
AJAX Handlers 1
WordPress Hooks 12
Scheduled Events 1
Maintenance & Trust
Support Me Maintenance & Trust
Maintenance Signals
Community Trust
Support Me Alternatives
Password Strength Settings for WooCommerce
wc-password-strength-settings
Help secure your WooCommerce site by enforcing stronger passwords and taking additional control of your strength requirements.
Disable User Login
disable-user-login
Disable user accounts without deleting them. One-click enable/disable, bulk actions, force logout, and customizable disabled message.
Resend Welcome Email
resend-welcome-email
Quickly send a new welcome email and password reset link for a user through the user's profile edit area.
Temporary Access for users
temporary-access-for-users
Plugin is use full for provide temporary access to user. Also we can disable the user to temporary based.
Fake User Detector
fake-user-detector
Detect and flag suspicious existing user accounts using simple checks to help clean up fake or low-quality registrations.
Support Me Developer Profile
3 plugins · 31K total installs
How We Detect Support Me
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/support-me/assets/css/wwsm-users.css/wp-content/plugins/support-me/assets/js/wwsm-users.js/wp-content/plugins/support-me/assets/js/wwsm-users.jswwsm-users-css?ver=wwsm-users-js?ver=HTML / DOM Fingerprints
add-account-panelwwsm-noticewwsm-usernameusername-resultwwsm-tokentoken-resultwwsm-expiresexpires-result+1 moredata-wwsm-dismisswwsm_users_params