
Uix UserCenter Security & Risk Analysis
wordpress.org/plugins/uix-usercenterSign-in, registration and publishing system with AJAX, support remote API.
Is Uix UserCenter Safe to Use in 2026?
Generally Safe
Score 100/100Uix UserCenter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "uix-usercenter" v1.0.3 plugin exhibits a mixed security posture. On the positive side, the absence of known CVEs and a clean taint analysis suggest that common, severe vulnerabilities like code injection and SQL injection are likely absent. The plugin also demonstrates good practices by exclusively using prepared statements for its SQL queries and a high percentage of properly escaped output.
However, significant concerns arise from the plugin's attack surface. A notable portion of its entry points, specifically 8 out of 19, lack authentication or capability checks. This includes 6 AJAX handlers and 2 REST API routes that are exposed without proper authorization. This could allow unauthenticated users to interact with potentially sensitive functionalities or trigger unexpected behavior. While no dangerous functions were identified, and file operations are limited, the unprotected entry points present a clear avenue for attackers to probe and potentially exploit.
The plugin's vulnerability history is empty, which is a positive indicator. This suggests a good track record, or at least no publicly disclosed issues to date. Coupled with the internal code analysis showing no critical or high severity taint flows, this reinforces the notion that the plugin has likely been developed with some attention to security. Nevertheless, the unprotected entry points remain a critical weakness that requires immediate attention to harden the plugin's security.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Significant unescaped output (13%)
Uix UserCenter Security Vulnerabilities
Uix UserCenter Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Uix UserCenter Attack Surface
AJAX Handlers 17
REST API Routes 2
WordPress Hooks 43
Maintenance & Trust
Uix UserCenter Maintenance & Trust
Maintenance Signals
Community Trust
Uix UserCenter Alternatives
Expire User Passwords
expire-user-passwords
Require certain users to change their passwords on a regular basis.
Prevent Concurrent Logins
prevent-concurrent-logins
Prevents users from staying logged into the same account from multiple places.
WP Frontend Profile
wp-front-end-profile
WP Frontend Profile allows users to edit/view their profile and register/login without going into the dashboard to do so.
Login to read more
login-to-read-more
Display content enclosed by the shortcode for registered users only.
Multibyte CAPTCHA login and Mail only register
user-mail-only-register
Multibyte CAPTCHA login form and register users with mail only.
Uix UserCenter Developer Profile
6 plugins · 540 total installs
How We Detect Uix UserCenter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/uix-usercenter/assets/css/uix-usercenter.css/wp-content/plugins/uix-usercenter/assets/js/uix-usercenter.js/wp-content/plugins/uix-usercenter/assets/js/uix-usercenter.jsuix-usercenter/assets/css/uix-usercenter.css?ver=uix-usercenter/assets/js/uix-usercenter.js?ver=HTML / DOM Fingerprints
uix-usercenter-login-formuix-usercenter-register-formuix-usercenter-password-reset-form<!-- Uix UserCenter notices -->data-uix-usercenter-actiondata-uix-usercenter-nonceuix_usercenter_ajax_urluix_usercenter_nonces/wp-json/uix-usercenter/v1/login/wp-json/uix-usercenter/v1/register/wp-json/uix-usercenter/v1/logout[uix_usercenter_login][uix_usercenter_register][uix_usercenter_password_reset]