
User Hierarchy Security & Risk Analysis
wordpress.org/plugins/user-hierarchyControl user management on a per-role basis. Allow users of a certain role to only add, edit or delete users from specific other roles.
Is User Hierarchy Safe to Use in 2026?
Generally Safe
Score 85/100User Hierarchy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the "user-hierarchy" plugin version 0.1.2 presents a very low security risk. The static analysis indicates a remarkably clean codebase with no identified dangerous functions, SQL queries performed using prepared statements, and all outputs properly escaped. Crucially, there are no identified entry points like AJAX handlers, REST API routes, or shortcodes that are not protected by authentication or permission checks, and the plugin does not perform file operations or external HTTP requests. The taint analysis also shows no flows with unsanitized paths, further reinforcing the lack of apparent code-level vulnerabilities.
The vulnerability history further supports this positive assessment, with zero known CVEs recorded against this plugin. This suggests a consistent track record of security by the developers or a lack of targeted exploitation. However, it is important to note that the plugin is at version 0.1.2, which is a very early version number. While the current analysis is highly positive, it's possible that more complex vulnerabilities could emerge as the plugin matures and its functionality expands. For a version this early, the absence of any issues is excellent, but ongoing vigilance and updates will be key as it evolves.
In conclusion, the "user-hierarchy" plugin v0.1.2 appears to be securely developed. Its minimal attack surface, robust coding practices (prepared statements, output escaping), and absence of any historical vulnerabilities make it a strong contender for a secure plugin. The primary, albeit minor, consideration is its early version number, which warrants continued monitoring for future updates. For its current state, it is highly recommended from a security perspective.
User Hierarchy Security Vulnerabilities
User Hierarchy Code Analysis
User Hierarchy Attack Surface
Maintenance & Trust
User Hierarchy Maintenance & Trust
Maintenance Signals
Community Trust
User Hierarchy Alternatives
View Admin As
view-admin-as
View the WordPress admin as a different role or visitor, switch between users, temporarily change your capabilities, set screen settings for roles.
Expire Users
expire-users
Set expiry dates for user logins.
HM Multiple Roles
hm-multiple-roles
It hides the default role dropdown list and displays a list of role checkboxes to select multiple roles for a user.
Restrict Media Library Access
restrict-media-library-access
Restricts access for Authors and Contributors so they can only see their own Media Library uploads.
Premmerce User Roles
premmerce-user-roles
This plugin has been developed for creating user roles from the WordPress admin area and assigning the arbitrary access rights to them.
User Hierarchy Developer Profile
7 plugins · 2K total installs
How We Detect User Hierarchy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/user-hierarchy/lib/css/user-hierarchy-admin.css/wp-content/plugins/user-hierarchy/lib/js/user-hierarchy-admin.js/wp-content/plugins/user-hierarchy/lib/js/user-hierarchy-admin.jsuser-hierarchy/lib/css/user-hierarchy-admin.css?ver=user-hierarchy/lib/js/user-hierarchy-admin.js?ver=HTML / DOM Fingerprints
jwuh-role-manager-fielddata-jwuh-role-manager-fieldjwuh_admin_params