
User Register Filter Security & Risk Analysis
wordpress.org/plugins/user-register-filterRestringe el registro de usuarios en tu WordPress en función de las reglas que especifiques: lista negra de dominios, de extensiones, de nombres, filt …
Is User Register Filter Safe to Use in 2026?
Generally Safe
Score 85/100User Register Filter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "user-register-filter" plugin v1.3 exhibits a mixed security posture. On the positive side, there are no identified vulnerabilities in its history, no dangerous functions detected, and all SQL queries utilize prepared statements, indicating good practices in these areas. The attack surface also appears to be minimal, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed, which is a significant security strength.
However, a major concern arises from the complete absence of output escaping for all nine identified outputs. This means that any data rendered by the plugin, whether user-provided or from other sources, is susceptible to cross-site scripting (XSS) attacks. Furthermore, the lack of any nonce or capability checks for potential entry points, while currently small, presents a risk if the attack surface were to expand in future versions. The absence of taint analysis results is not inherently negative but limits the ability to fully assess the risk of untrusted data flow within the plugin.
In conclusion, while the plugin benefits from a clean vulnerability history and robust handling of database operations and attack surface reduction, the lack of output escaping is a critical flaw that significantly undermines its security. The absence of checks on potential entry points also warrants attention. Users should be aware of the XSS risk until this is addressed. The clean history is encouraging, but the current code has a high-impact vulnerability.
Key Concerns
- All identified outputs are unescaped
- No nonce checks detected
- No capability checks detected
User Register Filter Security Vulnerabilities
User Register Filter Release Timeline
User Register Filter Code Analysis
Output Escaping
User Register Filter Attack Surface
WordPress Hooks 4
Maintenance & Trust
User Register Filter Maintenance & Trust
Maintenance Signals
Community Trust
User Register Filter Alternatives
Users Registration Date
users-registered-list
New sortable "Registered" date column on the Users page in wp-admin area to see when each user has registered on a site.
Page Authority – Allowed Domains
page-authority-allowed-domains
Restrict WordPress user accounts to administrator-approved email domains.
Multibyte CAPTCHA login and Mail only register
user-mail-only-register
Multibyte CAPTCHA login form and register users with mail only.
Disable Admin Email
disable-admin-email
Turns off the notification sent to the admin email when a new user account is registered.
Ban Subdomain Emails
ban-subdomain-emails
Prevent people from registering with emails that contain a subdomain to help reduce spam.
User Register Filter Developer Profile
1 plugin · 10 total installs
How We Detect User Register Filter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
tt_user_register_filter_ending_email_blacklisttt_user_register_filter_intelligent_filter