
Trusted Only Security & Risk Analysis
wordpress.org/plugins/trusted-onlyMakes your site content visible only for several users who are in your trusted list.
Is Trusted Only Safe to Use in 2026?
Generally Safe
Score 100/100Trusted Only has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "trusted-only" v1.1 plugin presents a generally positive security posture based on the provided static analysis. It demonstrates a lack of identified vulnerabilities in its history and a clean taint analysis, with no critical or high severity flows found. Furthermore, the plugin doesn't appear to have a significant attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events detected. The use of prepared statements for SQL queries is a strong security practice.
However, a significant concern arises from the "Output escaping" signal, where 100% of the outputs are not properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website if user-provided data is displayed without proper sanitization. While the plugin has a capability check, the lack of nonce checks on any entry points (though none were identified) could also be a concern in a broader context, especially if new entry points were to be introduced without adequate security measures.
In conclusion, the plugin benefits from a clean vulnerability history and a limited attack surface. The main weakness lies in the unescaped output, which introduces a notable risk of XSS. Addressing the output escaping issue should be a top priority to improve its overall security.
Key Concerns
- Output escaping is not properly implemented
Trusted Only Security Vulnerabilities
Trusted Only Code Analysis
Output Escaping
Trusted Only Attack Surface
WordPress Hooks 6
Maintenance & Trust
Trusted Only Maintenance & Trust
Maintenance Signals
Community Trust
Trusted Only Alternatives
Users by Date Registered
users-by-date-registered
Allows you to see the dates users registered on and filter the users by date.
BP Signup Member Type
bp-signup-member-type
Add a "Member Type" option to the BuddyPress registration form.
WP-LDAP
wp-ldap
Translates the WordPress user database to an LDAP store of the same; manage your LDAP DIT using your WordPress Dashboard.
BP Delegated XProfile
bp-delegated-xprofile
Enables delegating a user's Extended Profile for editing by other users.
Remove Dashboard Access
remove-dashboard-access-for-non-admins
Disable Dashboard access for users of a specific role or capability. Disallowed users are redirected to a chosen URL. Get set up in seconds.
Trusted Only Developer Profile
7 plugins · 2K total installs
How We Detect Trusted Only
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
trusted-only-message