
User Logs Security & Risk Analysis
wordpress.org/plugins/user-logsUser Logs plugin allows you to monitor user activity on your website. View user logins, logouts, comments and user registrations.
Is User Logs Safe to Use in 2026?
Generally Safe
Score 100/100User Logs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'user-logs' plugin v1.0.2 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests is a positive indicator. Furthermore, 100% of output is properly escaped, and a high percentage of SQL queries use prepared statements, mitigating common injection risks. The plugin also shows no known historical vulnerabilities, suggesting a history of secure development.
However, the static analysis does highlight some areas for concern. The presence of 3 taint flows with unsanitized paths, including 2 of high severity, is a significant risk. While the plugin doesn't appear to have publicly known CVEs, these internal findings suggest potential vulnerabilities that could be exploited. The lack of nonce and capability checks across all entry points, especially considering the presence of cron events, is another notable weakness. This implies that actions triggered by these events or potential future extensions could be performed without proper authorization checks, increasing the risk of unauthorized access or modification.
In conclusion, while 'user-logs' v1.0.2 has several good security practices, the identified taint flows and the absence of robust authorization checks on entry points are critical areas that need immediate attention to improve its overall security.
Key Concerns
- High severity taint flows found
- Unsanitized paths in taint flows
- No nonce checks
- No capability checks
User Logs Security Vulnerabilities
User Logs Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
User Logs Attack Surface
WordPress Hooks 9
Scheduled Events 1
Maintenance & Trust
User Logs Maintenance & Trust
Maintenance Signals
Community Trust
User Logs Alternatives
FluentAuth – The Ultimate Authorization & Security Plugin for WordPress
fluent-security
Enhance the Security and User Experience of Your Site with Login/Signup Security, Two-Factor Email Authentication, Social Logins and more...
Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity
logtivity
Logtivity is the activity log service for WordPress admins. Logtivity is a unified activity log platform that tracks activity and errors across all yo …
Social Proof Popups & Real-Time Notifications – Herd Effects
mwp-herd-effect
Boost conversions with real-time social proof popups and user activity notifications, encouraging visitor actions on your WordPress site.
Page View Count by Webline
page-view-count-by-webline
This plugin allows user to see how many times a given page is viewed on each page load with reports for admin to do detail analysis
Activity Log Pro – Event Logger, Activity Monitor & Audit Log
activity-log-pro
Professional WordPress Activity Log. Track logins, user actions, content changes, and system events to see who did what, when, and where.
User Logs Developer Profile
4 plugins · 1K total installs
How We Detect User Logs
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/user-logs/assets/css/admin-styles.css/wp-content/plugins/user-logs/assets/css/jquery-ui.min.css/wp-content/plugins/user-logs/assets/js/admin-scripts.js/wp-content/plugins/user-logs/assets/js/google-charts-loader.js/wp-content/plugins/user-logs/assets/js/admin-scripts.js/wp-content/plugins/user-logs/assets/js/google-charts-loader.jsuserlogs_admin_style?ver=jquery-ui?ver=userlogs_admin_script?ver=google_charts_loader?ver=HTML / DOM Fingerprints
userlogs_welcome_noticedata-plugin-page