[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fe840TUeOc2OBXcg3RaSsdCi-d5UP7L5YpjtXFqwOf0w":3,"$fKYtEAbe1m-cTjY2JMi9DHxDDIYvp9txY3SHq2oUlijE":209,"$fxxls55C6IUJ0YHCh--c6bgsoSlqWmELLmpSHVIcLZqo":214},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":37,"analysis":131,"fingerprints":194},"user-register-filter","User Register Filter","1.3","Tible Technologies","https:\u002F\u002Fprofiles.wordpress.org\u002Ftibletech\u002F","\u003Cp>Restringe el registro de usuarios en tu WordPress en función de las reglas que especifiques: lista negra de dominios, de extensiones, de nombres, filtrado inteligente anti bots, listas blancas…\u003C\u002Fp>\n\u003Ch4>Features included:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Deny registration if email ends with…\u003C\u002Fli>\n\u003Cli>Smart filtering (detects suspicious behaviours)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Suggestions?\u003C\u002Fh4>\n\u003Cp>If you have suggestions for a new feature or you found a bug, feel free to email us via \u003Ca href=\"https:\u002F\u002Ftibletech.com\u002Fcontact\" rel=\"nofollow ugc\">https:\u002F\u002Ftibletech.com\u002Fcontact\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>Stay tuned!\u003C\u002Fh4>\n\u003Cp>Want regular updates and interesting info about \u003Cem>Website Development\u003C\u002Fem>? Follow us on… \u003Ca href=\"https:\u002F\u002Fwww.facebook.com\u002Ftibletech\" title=\"Tible Technologies Facebook Page\" rel=\"nofollow ugc\">Facebook\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Ftwitter.com\u002Ftibletech\" title=\"Tible Technologies Twitter Page\" rel=\"nofollow ugc\">Twitter\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fplus.google.com\u002F+tibletech\" title=\"Tible Technologies Google Plus Page\" rel=\"nofollow ugc\">Google Plus\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fwww.linkedin.com\u002Fcompany\u002Ftible-technologies\" title=\"Tible Technologies LinkedIn Page\" rel=\"nofollow ugc\">LinkedIn\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Translations\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>English (EN): default, always included.\u003C\u002Fli>\n\u003Cli>Spanish (ES): we have Spanish blood.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>All our plugins are localized\u002Ftranslateable by default. This is very important for all users worldwide. So please contribute your language to the plugin to make it even more useful.\u003C\u002Fp>\n","Restringe el registro de usuarios en tu WordPress en función de las reglas que especifiques: lista negra de dominios, de extensiones, de nombres, filt &hellip;",10,1869,0,"2017-05-15T21:20:00.000Z","4.7.33","4.1","",[19,20,21,22,23],"ban","email","register","registration","users","https:\u002F\u002Ftibletech.com\u002Fes","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fuser-register-filter.zip",85,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":32,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":11,"avg_security_score":26,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"tibletech",1,30,84,"2026-08-24T13:37:09.726Z",[38,60,78,95,115],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":46,"downloaded":47,"rating":48,"num_ratings":49,"last_updated":50,"tested_up_to":51,"requires_at_least":52,"requires_php":53,"tags":54,"homepage":58,"download_link":59,"security_score":48,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"users-registered-list","Users Registration Date","1.0.1","Slava Abakumov","https:\u002F\u002Fprofiles.wordpress.org\u002Fslaffik\u002F","\u003Cp>The “Users Registration Date” plugin adds a new sortable “Registered” column to the users lists that you can see in wp-admin area.r\u003C\u002Fp>\n\u003Cp>You can sort users by this date in ascending (to see the oldest users first) and descending (the latest users first) order.\u003C\u002Fp>\n\u003Cp>The plugin honors global site date and time formats that you set on the Settings > General page.\u003C\u002Fp>\n\u003Ch3>Languages\u003C\u002Fh3>\n\u003Cp>You can translate the plugin into your language.\u003C\u002Fp>\n","New sortable \"Registered\" date column on the Users page in wp-admin area to see when each user has registered on a site.",2000,10394,100,5,"2025-12-30T09:39:00.000Z","6.9.5","3.3","5.6",[55,22,56,23,57],"registered-date","sort","users-list","https:\u002F\u002Fovirium.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fusers-registered-list.1.0.1.zip",{"slug":61,"name":62,"version":63,"author":64,"author_profile":65,"description":66,"short_description":67,"active_installs":34,"downloaded":68,"rating":13,"num_ratings":13,"last_updated":69,"tested_up_to":70,"requires_at_least":71,"requires_php":72,"tags":73,"homepage":76,"download_link":77,"security_score":48,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"page-authority-allowed-domains","Page Authority – Allowed Domains","2.0.2","Talisa @ Page Authority","https:\u002F\u002Fprofiles.wordpress.org\u002Ftwestford\u002F","\u003Cp>Restrict WordPress user accounts to administrator-approved email domains.\u003C\u002Fp>\n\u003Cp>Page Authority – Allowed Domains gives administrators a simple way to control which email domains are permitted when WordPress user accounts are created. When the allowlist is set, any attempt to create a user with an email outside the approved domains is blocked across the standard registration form, the REST API, and WooCommerce registration.\u003C\u002Fp>\n\u003Cp>It is designed for sites where only users from specific organizations, companies, clients, or teams should be added as WordPress users. Typical use cases include internal company portals where only staff email addresses should ever become accounts, agency-managed client sites that should reject public signups, membership or B2B sites that vet users by their email domain, and multisite networks that need consistent domain rules across sites.\u003C\u002Fp>\n\u003Cp>Existing users are never modified automatically. Instead, the Existing User Audit highlights accounts whose email domains are not on the allowlist so an administrator can review and act on them individually, including removing an account and reassigning its content.\u003C\u002Fp>\n\u003Cp>Features include:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Admin-managed allowed domain list\u003C\u002Fli>\n\u003Cli>Standard WordPress registration enforcement\u003C\u002Fli>\n\u003Cli>REST API user creation\u002Fupdate enforcement\u003C\u002Fli>\n\u003Cli>WooCommerce registration enforcement\u003C\u002Fli>\n\u003Cli>Existing User Audit tools\u003C\u002Fli>\n\u003Cli>Optional login enforcement\u003C\u002Fli>\n\u003Cli>Per-user unauthorized account removal with content reassignment\u003C\u002Fli>\n\u003Cli>Multisite-aware protections\u003C\u002Fli>\n\u003Cli>Lightweight architecture with no custom database tables\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Security Notes\u003C\u002Fh3>\n\u003Cp>The plugin includes:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Capability checks\u003C\u002Fli>\n\u003Cli>Nonce verification (verified before any state-changing logic runs)\u003C\u002Fli>\n\u003Cli>Sanitization and escaping\u003C\u002Fli>\n\u003Cli>Live revalidation before destructive actions\u003C\u002Fli>\n\u003Cli>Current-admin protection\u003C\u002Fli>\n\u003Cli>Multisite Super Admin protection\u003C\u002Fli>\n\u003Cli>Explicit content reassignment or delete confirmation before user removal\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Recommended operational practices:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Review the Existing User Audit before enabling login blocking\u003C\u002Fli>\n\u003Cli>Test custom registration and SSO flows before production rollout\u003C\u002Fli>\n\u003Cli>Maintain regular database backups before deleting users\u003C\u002Fli>\n\u003Cli>Restrict plugin management access to trusted administrators only\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Uninstall\u003C\u002Fh3>\n\u003Cp>Deleting the plugin removes its current options:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>pageauth_allowed_domains\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>pageauth_audit_log\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>pageauth_block_unauthorized_logins\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>It also cleans up internal flags, transients, user meta, and any leftover keys from prior plugin versions that used the \u003Ccode>paad_\u003C\u002Fcode> or \u003Ccode>aed_\u003C\u002Fcode> prefixes. On multisite, the matching network options are removed as well.\u003C\u002Fp>\n","Restrict WordPress user accounts to administrator-approved email domains.",279,"2026-06-28T19:23:00.000Z","7.0.2","6.0","7.4",[74,20,22,75,23],"domains","security","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fpage-authority-allowed-domains\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fpage-authority-allowed-domains.2.0.2.zip",{"slug":79,"name":80,"version":81,"author":82,"author_profile":83,"description":84,"short_description":85,"active_installs":34,"downloaded":86,"rating":13,"num_ratings":13,"last_updated":87,"tested_up_to":70,"requires_at_least":88,"requires_php":89,"tags":90,"homepage":93,"download_link":94,"security_score":48,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"user-mail-only-register","Multibyte CAPTCHA login and Mail only register","4.03","Katsushi Kawamori","https:\u002F\u002Fprofiles.wordpress.org\u002Fkatsushi-kawamori\u002F","\u003Ch4>Login form with Multibyte CAPTCHA\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Anti-Bot measures with original CAPTCHA.\u003C\u002Fli>\n\u003Cli>WordPress : \u003Ccode>wp-login.php\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>WordPress : \u003Ccode>wp-login.php?action=register\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>WordPress : \u003Ccode>wp-login.php?action=lostpassword\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Register\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Register only email address.\u003C\u002Fli>\n\u003Cli>Can check the terms of use agreement for user register.\u003C\u002Fli>\n\u003Cli>Anti-Bot measures with original CAPTCHA.\u003C\u002Fli>\n\u003Cli>WordPress : \u003Ccode>wp-login.php?action=register\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>shortcode : \u003Ccode>[umorregister]\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Filter for shortcode form\u003C\u002Fh4>\n\u003Cpre>\u003Ccode>\u002F** ==================================================\n * Filter for message.\n *\n *\u002F\nadd_filter( 'umor_register_success_msg', function(){ return 'Message for register success.'; }, 10, 1 );\nadd_filter( 'umor_login_success_login_msg', function(){ return 'Message for login success.'; }, 10, 1 );\nadd_filter( 'umor_register_error', function(){ return 'Message for register error.'; }, 10, 1 );\nadd_filter( 'umor_register_nomail', function(){ return 'Message for unentered mail.'; }, 10, 1 );\nadd_filter( 'umor_register_noterm', function(){ return 'Message for unentered term of use.'; }, 10, 1 );\nadd_filter( 'umor_register_form_label', function(){ return 'Message for form label.'; }, 10, 1 );\nadd_filter( 'umor_register_term_of_use', function(){ return 'Message for term of use.'; }, 10, 1 );\nadd_filter( 'umor_not_register_message', function(){ return 'Message for not register.'; }, 10, 1 );\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cpre>\u003Ccode>\u002F** ==================================================\n * Filter for login form message.\n *\n *\u002F\nadd_filter(\n    'umor_login_message',\n    function( $message, $text ) {\n        $message = '\u003Cp class=\"myclass\">';\n        $message .= $text;\n        $message .= '\u003C\u002Fp>';\n        return $message;\n    },\n    10,\n    2\n);\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cpre>\u003Ccode>\u002F** ==================================================\n * Filter for Term of use URL.\n *\n *\u002F\nadd_filter(\n    'umor_register_term_of_use_url',\n    function( $term_of_use_url ) {\n        if ( 'ja' === get_locale() ) {\n            $term_of_use_url = 'https:\u002F\u002Ftest.com\u002Fja\u002F';\n        }\n        return $term_of_use_url;\n    },\n    10,\n    1\n);\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cpre>\u003Ccode>\u002F** ==================================================\n * Filter for input text size.\n *\n *\u002F\nadd_filter( 'umor_register_input_size', function(){ return 17; }, 10, 1 );\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cpre>\u003Ccode>\u002F** ==================================================\n * Filter for class name.\n *\n *\u002F\nadd_filter( 'umor_register_notice_class_name', function(){ return 'mynotice'; }, 10, 1 );\nadd_filter( 'umor_register_form_class_name', function(){ return 'myform'; }, 10, 1 );\nadd_filter( 'umor_register_label_class_name', function(){ return 'mylabel'; }, 10, 1 );\nadd_filter( 'umor_register_input_class_name', function(){ return 'myinput'; }, 10, 1 );\nadd_filter( 'umor_register_check_form_class_name', function(){ return 'mycheckform'; }, 10, 1 );\nadd_filter( 'umor_register_check_class_name', function(){ return 'mycheck'; }, 10, 1 );\nadd_filter( 'umor_register_captcha_input_class_name', function(){ return 'mycaptcha_input'; }, 10, 1 );\nadd_filter( 'umor_register_submit_class_name', function(){ return 'mysubmit'; }, 10, 1 );\n\u003C\u002Fcode>\u003C\u002Fpre>\n","Multibyte CAPTCHA login form and register users with mail only.",5949,"2026-03-29T22:04:00.000Z","4.7","8.0",[91,20,92,21,23],"captcha","login","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fuser-mail-only-register\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fuser-mail-only-register.4.03.zip",{"slug":96,"name":97,"version":98,"author":99,"author_profile":100,"description":101,"short_description":102,"active_installs":103,"downloaded":104,"rating":13,"num_ratings":13,"last_updated":105,"tested_up_to":106,"requires_at_least":17,"requires_php":17,"tags":107,"homepage":17,"download_link":113,"security_score":114,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"disable-admin-email","Disable Admin Email","1.0.0","Ashyzan","https:\u002F\u002Fprofiles.wordpress.org\u002Fashyzan\u002F","\u003Cp>A simple plugin that disables the notification email sent to the admin, only when a new user account is registered.\u003Cbr \u002F>\nFor use it, simple activate it!\u003C\u002Fp>\n\u003Cp>If you like this plugin, please consider leaving a comment or review.\u003C\u002Fp>\n\u003Ch3>Github Repo\u003C\u002Fh3>\n\u003Cp>Here’s a link to the Github Repo \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FAshyzan\u002Fdisable-admin-email\" title=\"Github Repo\" rel=\"nofollow ugc\">githublink\u003C\u002Fa>\u003C\u002Fp>\n","Turns off the notification sent to the admin email when a new user account is registered.",20,711,"2025-01-06T18:30:00.000Z","6.7.5",[108,109,110,111,112],"admin-notification-email","disable-admin-email-when-user-register","disable-new-user-registration-email","new-user-registration-email","user-registration-admin-email","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdisable-admin-email.zip",92,{"slug":116,"name":117,"version":98,"author":118,"author_profile":119,"description":120,"short_description":121,"active_installs":11,"downloaded":122,"rating":48,"num_ratings":33,"last_updated":123,"tested_up_to":124,"requires_at_least":125,"requires_php":17,"tags":126,"homepage":129,"download_link":130,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"ban-subdomain-emails","Ban Subdomain Emails","jamiechong","https:\u002F\u002Fprofiles.wordpress.org\u002Fjamiechong\u002F","\u003Cp>A lot of registration spam comes from emails with a subdomain. Spammers control a domain such as buymyjunk.com and then attempt to register on your site with emails such as irenemwd@foster2.buymyjunk.com and jakemgm@foster7.buymyjunk.com. This plugin simply blocks all registrations using a subdomain.\u003C\u002Fp>\n\u003Cp>Reputable users will have a normal email address from a reasonable domain like @gmail.com, @mylegitbusiness.com, @outlook.com, @myschool.edu, etc.\u003C\u002Fp>\n\u003Cp>There is no configuration and no setup. It simply just works. The plugin logs all blocked registrations so you can find potential false-positives. Find a link to this log file on the Plugins page where you activate\u002Fdeactivate this plugin.\u003C\u002Fp>\n","Prevent people from registering with emails that contain a subdomain to help reduce spam.",2143,"2016-04-27T04:07:00.000Z","4.5.33","4.0",[127,19,20,22,128],"akismet","spam","https:\u002F\u002Fgithub.com\u002Fjamiechong\u002Fwp-ban-subdomain-emails","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fban-subdomain-emails.zip",{"attackSurface":132,"codeSignals":156,"taintFlows":182,"riskAssessment":183,"analyzedAt":193},{"hooks":133,"ajaxHandlers":152,"restRoutes":153,"shortcodes":154,"cronEvents":155,"entryPointCount":13,"unprotectedCount":13},[134,140,144,148],{"type":135,"name":136,"callback":137,"priority":11,"file":138,"line":139},"action","register_post","tt_user_register_filter","tt-user-register-filter.php",70,{"type":135,"name":141,"callback":142,"file":138,"line":143},"admin_menu","tt_user_register_filter_admin_menu",89,{"type":135,"name":145,"callback":146,"file":138,"line":147},"admin_init","tt_user_register_filter_content_settings",144,{"type":135,"name":149,"callback":150,"file":138,"line":151},"plugins_loaded","wan_load_textdomain",151,[],[],[],[],{"dangerousFunctions":157,"sqlUsage":158,"outputEscaping":160,"fileOperations":13,"externalRequests":13,"nonceChecks":13,"capabilityChecks":13,"bundledLibraries":181},[],{"prepared":13,"raw":13,"locations":159},[],{"escaped":13,"rawEcho":161,"locations":162},9,[163,166,168,170,172,174,176,178,179],{"file":138,"line":164,"context":165},99,"raw output",{"file":138,"line":167,"context":165},101,{"file":138,"line":169,"context":165},108,{"file":138,"line":171,"context":165},112,{"file":138,"line":173,"context":165},113,{"file":138,"line":175,"context":165},114,{"file":138,"line":177,"context":165},121,{"file":138,"line":177,"context":165},{"file":138,"line":180,"context":165},123,[],[],{"summary":184,"deductions":185},"The \"user-register-filter\" plugin v1.3 exhibits a mixed security posture. On the positive side, there are no identified vulnerabilities in its history, no dangerous functions detected, and all SQL queries utilize prepared statements, indicating good practices in these areas. The attack surface also appears to be minimal, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed, which is a significant security strength.\n\nHowever, a major concern arises from the complete absence of output escaping for all nine identified outputs. This means that any data rendered by the plugin, whether user-provided or from other sources, is susceptible to cross-site scripting (XSS) attacks. Furthermore, the lack of any nonce or capability checks for potential entry points, while currently small, presents a risk if the attack surface were to expand in future versions. The absence of taint analysis results is not inherently negative but limits the ability to fully assess the risk of untrusted data flow within the plugin.\n\nIn conclusion, while the plugin benefits from a clean vulnerability history and robust handling of database operations and attack surface reduction, the lack of output escaping is a critical flaw that significantly undermines its security. The absence of checks on potential entry points also warrants attention. Users should be aware of the XSS risk until this is addressed. The clean history is encouraging, but the current code has a high-impact vulnerability.",[186,189,191],{"reason":187,"points":188},"All identified outputs are unescaped",7,{"reason":190,"points":49},"No nonce checks detected",{"reason":192,"points":49},"No capability checks detected","2026-03-17T01:23:59.519Z",{"wat":195,"direct":200},{"assetPaths":196,"generatorPatterns":197,"scriptPaths":198,"versionParams":199},[],[],[],[],{"cssClasses":201,"htmlComments":202,"htmlAttributes":203,"restEndpoints":206,"jsGlobals":207,"shortcodeOutput":208},[],[],[204,205],"tt_user_register_filter_ending_email_blacklist","tt_user_register_filter_intelligent_filter",[],[],[],{"error":210,"url":211,"statusCode":212,"statusMessage":213,"message":213},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fuser-register-filter\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":13,"versions":215},[]]