
User Blocker Security & Risk Analysis
wordpress.org/plugins/user-blockerTo block users from admin side except admin users for specific day,time, and date or permanently.
Is User Blocker Safe to Use in 2026?
Generally Safe
Score 92/100User Blocker has a strong security track record. Known vulnerabilities have been patched promptly.
The "user-blocker" v2.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and a high percentage of properly escaped output. The absence of critical or high-severity taint flows is also encouraging. However, significant concerns arise from the presence of an unprotected AJAX handler, which represents a direct entry point into the application without proper authentication or authorization checks. The plugin's history includes a medium-severity 'Injection' vulnerability, indicating past weaknesses in handling user-supplied data, even though it is currently patched. This, combined with the unprotected AJAX handler, suggests a potential for attackers to exploit these weaknesses if not addressed.
Key Concerns
- Unprotected AJAX handler
- Past medium severity injection vulnerability
- Lack of capability checks on entry points
User Blocker Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
User Blocker <= 1.5.5 - Authenticated (Admin+) CSV Injection
User Blocker Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
User Blocker Attack Surface
AJAX Handlers 2
WordPress Hooks 27
Maintenance & Trust
User Blocker Maintenance & Trust
Maintenance Signals
Community Trust
User Blocker Alternatives
DW Block User Account
block-user-account
This plugin blocks user accounts and prevents users from accessing the WP ADMIN
Restrict Usernames Emails Characters
restrict-usernames-emails-characters
Restrict the usernames, email addresses, characters and symbols or email from specific domain names or language in registration ...
BP Block Users
bp-block-users
Allows BuddyPress administrators to block users indefinitely, or for a specified period of time.
User Blocker Developer Profile
7 plugins · 14K total installs
How We Detect User Blocker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/user-blocker/assets/css/user-blocker.css/wp-content/plugins/user-blocker/assets/js/user-blocker.js/wp-content/plugins/user-blocker/assets/js/user-blocker.jsuser-blocker/assets/css/user-blocker.css?ver=user-blocker/assets/js/user-blocker.js?ver=HTML / DOM Fingerprints
ublk-welcome-pageublk_ajax_object