
CC User Data Security & Risk Analysis
wordpress.org/plugins/user-dataAdd certain fields and images to your user profiles. Also gives access via shortcode to display a list of users/authors anywhere on your site.
Is CC User Data Safe to Use in 2026?
Generally Safe
Score 85/100CC User Data has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "user-data" plugin version 1.1.1 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, external HTTP requests, and critical taint flows is highly commendable. The presence of capability checks, even if only one, and the proper use of prepared statements for its SQL queries indicate good development practices for handling data access. However, the most significant concern lies in the output escaping, where only 54% of outputs are properly escaped. This leaves a considerable portion of user-facing data potentially vulnerable to cross-site scripting (XSS) attacks if user-supplied data is not sufficiently sanitized before being displayed.
The plugin's vulnerability history is clean, with zero recorded CVEs. This is a positive indicator, suggesting that the plugin has historically been well-maintained and free from exploitable flaws. However, the lack of past vulnerabilities does not guarantee future security. The absence of nonce checks on its single entry point (shortcode) is also a potential oversight, though without knowing the specific functionality of the shortcode, its impact is difficult to fully assess. Overall, while the "user-data" plugin has a solid foundation with secure data handling, the moderate output escaping is a notable weakness that requires attention to mitigate XSS risks.
Key Concerns
- Moderate output escaping (54%)
- No nonce checks on shortcode
CC User Data Security Vulnerabilities
CC User Data Release Timeline
CC User Data Code Analysis
SQL Query Safety
Output Escaping
CC User Data Attack Surface
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
CC User Data Maintenance & Trust
Maintenance Signals
Community Trust
CC User Data Alternatives
WP About Author
wp-about-author
Easily display customizable author bios below your posts
Author Bio Widget
author-bio-widget
A simple sidebar widget to display page or post author's bio and link through to other content from the author.
Simple Author Box
simple-author-box
Add a responsive author box or guest author box with social icons to any post. Great author box for any site!
Meks Smart Author Widget
meks-smart-author-widget
Easily display your author/user profile info inside WordPress widget.
Starbox – the Author Box for Humans
starbox
Starbox is the Author Box for Humans. Professional Themes to choose from, HTML5, Social Media Profiles, Google Authorship
CC User Data Developer Profile
4 plugins · 330 total installs
How We Detect CC User Data
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/user-data/cc-user-data.csscc-user-data/cc-user-data.css?ver=0.1.1HTML / DOM Fingerprints
authors_thumbsauthor_thumbauthor_thumb_imgauthor_nameauthor_titleauthor_infoauthor_sort_author_picture+7 moredata-show_thumbsdata-show_picturedata-show_biodata-show_titledata-show_emaildata-show_name+2 more<div class='authors_thumbs'><a class='author_thumb ' href='#'>