
User Last Visit Security & Risk Analysis
wordpress.org/plugins/user-last-visitThe plugin keeps record on each user last visit time using logged-in status, user ID and user meta data. Multisite compatible.
Is User Last Visit Safe to Use in 2026?
Generally Safe
Score 85/100User Last Visit has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "user-last-visit" v1.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, not executing raw SQL queries, and not making external HTTP requests. The presence of nonce checks and a lack of reported historical vulnerabilities suggest a developer who is at least somewhat security-aware. However, significant concerns arise from the attack surface analysis. A single AJAX handler is present and lacks any authentication checks, presenting a direct pathway for unauthorized actions. Furthermore, the taint analysis indicates flows with unsanitized paths, although no critical or high severity issues were identified in this specific analysis, the presence of such flows coupled with unprotected entry points is worrying. The plugin's current state, with its unprotected AJAX endpoint and unsanitized path flows, requires immediate attention despite the absence of known CVEs.
Key Concerns
- AJAX handler without auth checks
- Taint flows with unsanitized paths
- Low output escaping percentage
- Capability checks are missing
User Last Visit Security Vulnerabilities
User Last Visit Code Analysis
Output Escaping
Data Flow Analysis
User Last Visit Attack Surface
AJAX Handlers 1
WordPress Hooks 10
Maintenance & Trust
User Last Visit Maintenance & Trust
Maintenance Signals
Community Trust
User Last Visit Alternatives
User Switching
user-switching
Instant switching between user accounts in WordPress and WooCommerce.
When Last Login
when-last-login
Show a users last login date by creating a sortable column in your WordPress users list.
Delete Me
delete-me
Allow users with specific WordPress roles to delete themselves from the Your Profile page or anywhere Shortcodes can be used.
Require Login for WooCommerce
woo-for-logged-users
Set the WooCommerce Shop only for logged-in users. Just activate the plugin.
User Access Shortcodes
user-access-shortcodes
The simplest way of controlling who sees what in your posts/pages. Restrict content to logged in users only (or guests, or by roles) with simple short …
User Last Visit Developer Profile
3 plugins · 80 total installs
How We Detect User Last Visit
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/user-last-visit/assets/js/admin-page.js/wp-content/plugins/user-last-visit/assets/css/admin-page.css/wp-content/plugins/user-last-visit/assets/js/admin-page.jsuser-last-visit/assets/js/admin-page.js?ver=user-last-visit/assets/css/admin-page.css?ver=HTML / DOM Fingerprints
data-ulv-idulvAllLoginsulvSettingsText