User Role for Flamingo Security & Risk Analysis

wordpress.org/plugins/user-role-for-flamingo

Configure special user role to access the flamingo contacts and messages wihtout admin permissions.

700 active installs v1.0.1 PHP 7.0+ WP 5.0+ Updated Nov 26, 2023
capabilitiescontact-form-7flamingoformsuser-role
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is User Role for Flamingo Safe to Use in 2026?

Generally Safe

Score 85/100

User Role for Flamingo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'user-role-for-flamingo' plugin v1.0.1 exhibits a strong security posture. The absence of any identified dangerous functions, raw SQL queries, or unescaped output indicates that the developers have followed good security practices in these areas. Furthermore, the plugin demonstrates zero known vulnerabilities and a clean history, suggesting a commitment to maintaining a secure codebase. The limited attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, no unprotected entry points, significantly reduces the potential for exploitation.

The code analysis reveals a lack of nonce checks. While the plugin does implement capability checks, the absence of nonce validation on its limited entry points (which are zero, making this a moot point in practice) is a minor concern in theory. However, given the absence of any actual entry points and the strong capability checks observed, this is a theoretical rather than a practical risk. Taint analysis also yielded no concerning results, indicating no identified vulnerabilities related to unsanitized data flows.

In conclusion, the 'user-role-for-flamingo' plugin v1.0.1 appears to be a well-secured plugin. Its strengths lie in its minimal attack surface, robust coding practices regarding SQL and output escaping, and a completely clean vulnerability history. The only noted theoretical weakness is the absence of nonce checks, which is mitigated by the overall lack of exploitable entry points and existing capability checks.

Key Concerns

  • No nonce checks implemented
Vulnerabilities
None known

User Role for Flamingo Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

User Role for Flamingo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
9 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped9 total outputs
Attack Surface

User Role for Flamingo Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedincludes\class-ur4f.php:70
actionadmin_menuincludes\class-ur4f.php:71
actionadmin_initincludes\class-ur4f.php:72
filteruser_has_capincludes\class-ur4f.php:73
Maintenance & Trust

User Role for Flamingo Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedNov 26, 2023
PHP min version7.0
Downloads5K

Community Trust

Rating60/100
Number of ratings2
Active installs700
Developer Profile

User Role for Flamingo Developer Profile

Yannick Zipf

2 plugins · 730 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect User Role for Flamingo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/user-role-for-flamingo/admin/css/ur4f-admin.css/wp-content/plugins/user-role-for-flamingo/admin/js/ur4f-admin.js/wp-content/plugins/user-role-for-flamingo/public/css/ur4f-public.css/wp-content/plugins/user-role-for-flamingo/public/js/ur4f-public.js
Script Paths
/wp-content/plugins/user-role-for-flamingo/admin/js/ur4f-admin.js/wp-content/plugins/user-role-for-flamingo/public/js/ur4f-public.js
Version Parameters
user-role-for-flamingo/admin/css/ur4f-admin.css?ver=user-role-for-flamingo/admin/js/ur4f-admin.js?ver=user-role-for-flamingo/public/css/ur4f-public.css?ver=user-role-for-flamingo/public/js/ur4f-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
ur4f_settings_pageur4f_option_checkbox
Data Attributes
data-ur4f-setting-namedata-ur4f-setting-value
JS Globals
UR4F_AJAX_URLUR4F_AdminUR4F_Settings
FAQ

Frequently Asked Questions about User Role for Flamingo