
User Recording For WordPress Security & Risk Analysis
wordpress.org/plugins/user-recordingUser recording specially created for WordPress sites.
Is User Recording For WordPress Safe to Use in 2026?
Generally Safe
Score 85/100User Recording For WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "user-recording" plugin v1.0.5 exhibits a mixed security posture. While it demonstrates good practice by exclusively using prepared statements for all SQL queries and shows no known vulnerabilities in its history, several significant security concerns are present in its static analysis.
The plugin has a considerable attack surface, with 5 AJAX handlers identified. Alarmingly, all 5 of these AJAX handlers lack authentication checks, meaning any unauthenticated user could potentially trigger these functions. This absence of capability checks on these critical entry points is a major security weakness. Additionally, while the taint analysis did not reveal any unsanitized paths, the limited scope of analysis (only 1 flow analyzed) and the significant number of file operations (11) without explicit mention of sanitization for those operations warrant caution.
The plugin's lack of recorded vulnerabilities is positive, suggesting that historically it may not have had exploitable flaws or that they were promptly addressed. However, this does not mitigate the current identified risks from the static analysis. The presence of unprotected AJAX endpoints represents a direct and immediate threat that needs to be addressed. In conclusion, the plugin has a strength in its SQL query handling and vulnerability history, but this is heavily outweighed by the critical risk posed by unprotected AJAX handlers and a lack of comprehensive security checks on its entry points.
Key Concerns
- AJAX handlers without auth checks
- No nonce checks on AJAX handlers
- Low output escaping coverage
- Capability checks present but not on all entry points
User Recording For WordPress Security Vulnerabilities
User Recording For WordPress Release Timeline
User Recording For WordPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
User Recording For WordPress Attack Surface
AJAX Handlers 5
WordPress Hooks 7
Scheduled Events 1
Maintenance & Trust
User Recording For WordPress Maintenance & Trust
Maintenance Signals
Community Trust
User Recording For WordPress Alternatives
Lucky Orange
lucky-orange
Less time crunching numbers, more time growing your business.
Opti-Behavior – Self-Hosted Heatmaps, Session Recording & Analytics (GDPR-Native ,Free Hotjar & Clarity Alternative)
opti-behavior
Free self-hosted heatmaps, click tracking, session recordings & funnels. GDPR-ready. No session limits. Your data stays on your server.
UXsniff AI-powered Heatmaps and Session Recordings
ux-sniff
Short Description: AI-powered Heatmaps, Session Recordings & A/B Testing
Session Rewind
session-rewind
Optimize your web experience with video recordings of user behavior.
Analytics Integrator
analytics-integrator
Integrate your favourite session recording and analytics tool with ease. This plugin allows you to integrate the most popular services: Smartlook, Ful …
User Recording For WordPress Developer Profile
19 plugins · 12K total installs
How We Detect User Recording For WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/user-recording/js/Bundle/recorder_bundle.js/wp-content/plugins/user-recording/img/icon.png/wp-content/plugins/user-recording/screens/player.php/wp-content/plugins/user-recording/js/lib/velocity.min.js/wp-content/plugins/user-recording/js/Bundle/reactplayer_bundle.js/wp-content/plugins/user-recording/js/lib/bootstrap/css/bootstrap.css/wp-content/plugins/user-recording/js/lib/bootstrap/css/bootstrap.min.cssjs/Bundle/recorder_bundle.jsjs/lib/velocity.min.jsjs/Bundle/reactplayer_bundle.jsHTML / DOM Fingerprints
ssrLoadingScreenid="smart-session-recording-id"smartformsrecordingparams/wp-json/rednao/v1/recording/