
TR Register Only Security & Risk Analysis
wordpress.org/plugins/tr-register-onlyRestrict your WordPress site to registered/logged-in users only. Perfect for private communities, staging sites, and intranet portals.
Is TR Register Only Safe to Use in 2026?
Generally Safe
Score 100/100TR Register Only has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tr-register-only" v2.0.0 plugin exhibits a strong security posture based on the provided static analysis. The complete absence of any AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly limits the plugin's attack surface. Furthermore, the code signals indicate robust security practices, with all SQL queries utilizing prepared statements, all output properly escaped, and a capability check implemented. The lack of file operations and external HTTP requests further reduces potential vulnerabilities. The vulnerability history is also exceptionally clean, with zero known CVEs, suggesting a well-maintained and secure plugin over time.
While the static analysis reveals no critical or high-severity issues, the complete absence of any identified flows in the taint analysis, coupled with zero nonce checks, warrants a cautious approach. A zero taint flow could indicate a very small or straightforward codebase, or it might suggest that the analysis tools were unable to detect potential flows within this specific plugin. The lack of nonce checks, while not an issue given the current attack surface, is a standard WordPress security mechanism that is absent here. Overall, the plugin appears secure and well-developed with good adherence to security best practices. The primary area for potential concern, though not definitively identified as a risk in this analysis, is the lack of observable taint flows and nonce checks, which could be areas for further investigation if the plugin's functionality were to expand.
Key Concerns
- No nonce checks implemented
TR Register Only Security Vulnerabilities
TR Register Only Release Timeline
TR Register Only Code Analysis
Output Escaping
TR Register Only Attack Surface
WordPress Hooks 7
Maintenance & Trust
TR Register Only Maintenance & Trust
Maintenance Signals
Community Trust
TR Register Only Alternatives
My Private Site – Make Your Whole Site Private, Force Login & Block Registration Spam
jonradio-private-site
Make your WordPress site private in one click, block registration spam, and clean up existing spam accounts with staged safeguards that protect online …
Build Private Store For WooCommerce
build-private-store-for-woocommerce
Restrict WooCommerce store access to logged-in users only. Hide prices, hide products, require manual approval, and control who sees what — with zero …
BuddyForms Custom Login
buddyforms-custom-login-page
Custom Login, Custom Login Redirect, Custom Registartion Link, Registation Forms
WP-Members Membership Plugin
wp-members
The original WordPress membership plugin with content restriction, user login, custom registration fields, user profiles, and more.
Intranet & Private Site – All-In-One Intranet
all-in-one-intranet
Turn WordPress into a private intranet in one click. Restrict access to logged-in members, with auto-logout and login redirect.
TR Register Only Developer Profile
1 plugin · 30 total installs
How We Detect TR Register Only
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tr-register-only/assets/admin.csstr-register-only/assets/admin.css?ver=HTML / DOM Fingerprints
/wp-json/