
TR Register Only Security & Risk Analysis
wordpress.org/plugins/tr-register-onlyRestrict your WordPress site to registered/logged-in users only. Perfect for private communities, staging sites, and intranet portals.
Is TR Register Only Safe to Use in 2026?
Generally Safe
Score 100/100TR Register Only has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tr-register-only" v2.0.0 plugin exhibits a strong security posture based on the provided static analysis. The complete absence of any AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly limits the plugin's attack surface. Furthermore, the code signals indicate robust security practices, with all SQL queries utilizing prepared statements, all output properly escaped, and a capability check implemented. The lack of file operations and external HTTP requests further reduces potential vulnerabilities. The vulnerability history is also exceptionally clean, with zero known CVEs, suggesting a well-maintained and secure plugin over time.
While the static analysis reveals no critical or high-severity issues, the complete absence of any identified flows in the taint analysis, coupled with zero nonce checks, warrants a cautious approach. A zero taint flow could indicate a very small or straightforward codebase, or it might suggest that the analysis tools were unable to detect potential flows within this specific plugin. The lack of nonce checks, while not an issue given the current attack surface, is a standard WordPress security mechanism that is absent here. Overall, the plugin appears secure and well-developed with good adherence to security best practices. The primary area for potential concern, though not definitively identified as a risk in this analysis, is the lack of observable taint flows and nonce checks, which could be areas for further investigation if the plugin's functionality were to expand.
Key Concerns
- No nonce checks implemented
TR Register Only Security Vulnerabilities
TR Register Only Code Analysis
Output Escaping
TR Register Only Attack Surface
WordPress Hooks 7
Maintenance & Trust
TR Register Only Maintenance & Trust
Maintenance Signals
Community Trust
TR Register Only Alternatives
BuddyForms Custom Login
buddyforms-custom-login-page
Custom Login, Custom Login Redirect, Custom Registartion Link, Registation Forms
WP-Members Membership Plugin
wp-members
The original WordPress membership plugin with content restriction, user login, custom registration fields, user profiles, and more.
My Private Site
jonradio-private-site
Make your WordPress site private with one click for family, projects, or teams. Protection for content, login, and registration.
Private Website – Login Required
private-website
This plugin requires users to be logged in to view the website. Activate the plugin to enforce login, and deactivate it to remove the restriction.
H6 Private Store for WooCommerce
h6-private-store-for-woocommerce
Create private, members-only WooCommerce stores without subscriptions, theme overrides, or custom code.
TR Register Only Developer Profile
1 plugin · 20 total installs
How We Detect TR Register Only
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tr-register-only/assets/admin.csstr-register-only/assets/admin.css?ver=HTML / DOM Fingerprints
/wp-json/