
Theme per user Security & Risk Analysis
wordpress.org/plugins/theme-per-userLoad one Theme for a specific user. You must set the theme from User Profile then logout and login again in order to take effect.
Is Theme per user Safe to Use in 2026?
Generally Safe
Score 98/100Theme per user has a strong security track record. Known vulnerabilities have been patched promptly.
The security posture of the 'theme-per-user' plugin v1.0.4 presents a mixed picture. On one hand, the plugin demonstrates strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and having no identified dangerous functions, file operations, or external HTTP requests. The absence of a significant attack surface through AJAX, REST API, shortcodes, and cron events is also a positive indicator. However, a critical concern arises from the vulnerability history. The plugin has a known critical CVE related to Deserialization of Untrusted Data, and crucially, this vulnerability is listed as 'currently unpatched'. This single unpatched critical vulnerability significantly elevates the risk associated with using this plugin.
Key Concerns
- Unpatched critical CVE (Deserialization of Untrusted Data)
- Output not properly escaped
- No nonce checks found
Theme per user Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Theme per user <= 1.0.1 - Unauthenticated PHP Object Injection
Theme per user Code Analysis
Output Escaping
Theme per user Attack Surface
WordPress Hooks 11
Maintenance & Trust
Theme per user Maintenance & Trust
Maintenance Signals
Community Trust
Theme per user Alternatives
Inactive Logout
inactive-logout
Automatically logout idle user sessions, with logout redirections and concurrent limit logins all in one place.
Role Based Redirect
role-based-redirect
Redirect users after login/logout by role. Optionally hide admin bar and block dashboard access for selected roles.
Basic Front-End Login
basic-front-end-login
Adds a basic front-end login form to any page, post or widget and redirects to the page you choose.
Redirect WordPress Sign-up for iThemes Security
redirect-wp-sign-up-for-ithemes-security
This plugin redirects WordPress Sign-up to homepage if is activated "Hide Backend" module in iThemes Security settings.
WP – Redirect to homepage after login
wp-redirect-to-homepage-after-login
This lightweight plugin allow you to redirect all users to your site's homepage after the login step.
Theme per user Developer Profile
5 plugins · 1K total installs
How We Detect Theme per user
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
theme_per_user