
UM User Switching Security & Risk Analysis
wordpress.org/plugins/um-user-switchingAddon that integrates User Switching to Ultimate Member
Is UM User Switching Safe to Use in 2026?
Generally Safe
Score 85/100UM User Switching has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "um-user-switching" plugin, in version 1.0.1.1, demonstrates a generally positive security posture based on the provided static analysis and vulnerability history. There are no reported CVEs, indicating a lack of known critical or high-severity vulnerabilities in its past. The static analysis also shows a clean slate regarding dangerous functions, SQL injection risks (all queries use prepared statements), and external HTTP requests. The attack surface is reported as zero, which is highly unusual and suggests the plugin may not have active components exposed for direct user interaction or integration, or the analysis might have limitations in identifying certain entry points.
However, the static analysis does reveal a concern with output escaping, where only 54% of the outputs are properly escaped. This leaves a portion of the plugin's output potentially vulnerable to cross-site scripting (XSS) attacks if user-supplied data is not adequately sanitized before being displayed. While there are no explicit taint flows or specific vulnerability types flagged, the unescaped output is a tangible risk that requires attention. The absence of capability checks and nonce checks, combined with zero unprotected entry points, is puzzling. If there were any entry points, their lack of authorization checks would be a major concern. Given the zero-entry-point finding, the lack of these checks might be irrelevant in practice, but it's a point to note for future development.
Key Concerns
- Unescaped output detected
UM User Switching Security Vulnerabilities
UM User Switching Code Analysis
Output Escaping
UM User Switching Attack Surface
WordPress Hooks 10
Maintenance & Trust
UM User Switching Maintenance & Trust
Maintenance Signals
Community Trust
UM User Switching Alternatives
User Switching
user-switching
Instant switching between user accounts in WordPress and WooCommerce.
Admin Bar User Switching
admin-bar-user-switching
Extends the excellent User Switching plugin by John Blackbourn by adding a User Switching to the admin bar for quick and easy user switching.
Multisite User Role Manager
multisite-user-role-manager
Manage user roles for each blog from a single screen on multisite (WPMU) setups
User Role Switcher
wp-user-role-switcher
Instant switching between user roles in WordPress.
Multisite User Management
multisite-user-management
Automatically add users to each site in your WordPress network.
UM User Switching Developer Profile
17 plugins · 2K total installs
How We Detect UM User Switching
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
generator-plugin-wpum-user-switching/includes/class-um-user-switching.php?ver=HTML / DOM Fingerprints
user_switching<a href="" class="" id="user_switching"><i class="um-faicon-sign-in" aria-hidden="true"></i> Switch To</a>