
User Activity Security & Risk Analysis
wordpress.org/plugins/user-activityList number of posts per user. You can limit the search by date, post type and user name.
Is User Activity Safe to Use in 2026?
Use With Caution
Score 64/100User Activity has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "user-activity" plugin v1.0.1 presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and having a capability check implemented. The absence of dangerous functions, file operations, and external HTTP requests is also a strong indicator of a security-conscious design. However, concerns arise from the taint analysis, which identified two high-severity flows with unsanitized paths. This suggests potential vulnerabilities where user-supplied data could be manipulated in unintended ways. The plugin also has a history of vulnerabilities, with one unpatched medium severity CVE from February 2023, indicating a pattern of issues related to the use of less trusted sources. While the attack surface appears minimal with no directly exposed entry points in the static analysis, the identified taint flows and past vulnerability history necessitate caution.
Key Concerns
- Unsanitized taint flow (High Severity)
- Unpatched CVE (Medium Severity)
- Unescaped output (partial)
User Activity Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
User Activity <= 1.0.1 - IP Address Spoofing
User Activity Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
User Activity Attack Surface
WordPress Hooks 4
Maintenance & Trust
User Activity Maintenance & Trust
Maintenance Signals
Community Trust
User Activity Alternatives
Emu2 – Email Users 2
emu2-email-users-2
Send email to users, manually or on schedule (digest of newest posts). Users can send emails to each other. Export function included. STILL BETA!!!
List-all-authors
list-all-authors
Das Plugin ermoeglicht die Auflistung aller Authoren, auch solcher, die noch keine Artikel geschrieben haben. The plugin lets you lists all authors, even those without posts.
WP Mechanic
wp-mechanic
WP Mechanic is a combination of WordPress and Android Playstore Applications. Experience a set of hybrid software applications.
View Admin As
view-admin-as
View the WordPress admin as a different role or visitor, switch between users, temporarily change your capabilities, set screen settings for roles.
Product Customer List for WooCommerce
wc-product-customer-list
Display a list of customers who bought a specific product at the bottom of the product edit page in WooCommerce and send them e-mails.
User Activity Developer Profile
3 plugins · 130 total installs
How We Detect User Activity
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/user-activity/js/user-activity.js/wp-content/plugins/user-activity/js/user-activity.jsuser-activity/js/user-activity.js?ver=1.0HTML / DOM Fingerprints
user-activity-pagedata-user-idbu_user_activity_params