
userlog Security & Risk Analysis
wordpress.org/plugins/userlogAllows you to see wich users have logged in when and from where.
Is userlog Safe to Use in 2026?
Generally Safe
Score 85/100userlog has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The userlog plugin version 1.4 presents a mixed security posture. On the positive side, the plugin has no recorded CVEs, indicating a generally stable security history. The static analysis reveals a minimal attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication. Furthermore, the majority of SQL queries utilize prepared statements, and there are no critical or high severity taint flows identified. However, significant concerns arise from the complete lack of output escaping for all identified outputs. This is a critical weakness, as it opens the door to Cross-Site Scripting (XSS) vulnerabilities if any data processed by the plugin is directly outputted to the user's browser without proper sanitization. Additionally, the absence of nonce checks and the single capability check suggest a potential for authorization bypasses if specific actions within the plugin are not adequately protected, especially if new entry points are introduced in future versions. While the current vulnerability history is clean, the lack of robust output escaping is a serious oversight that requires immediate attention.
Key Concerns
- No output escaping for any outputs
- No nonce checks found
- Limited capability checks (1 total)
userlog Security Vulnerabilities
userlog Release Timeline
userlog Code Analysis
SQL Query Safety
Output Escaping
userlog Attack Surface
WordPress Hooks 6
Maintenance & Trust
userlog Maintenance & Trust
Maintenance Signals
Community Trust
userlog Alternatives
Expire User Passwords
expire-user-passwords
Require certain users to change their passwords on a regular basis.
Prevent Concurrent Logins
prevent-concurrent-logins
Prevents users from staying logged into the same account from multiple places.
User Session Control
user-session-control
View and manage all active user sessions in a custom admin screen.
Log Users Stats
log-user-stats
Display 'Total Minutes', 'Number of Logins', and 'Average Minutes Per Login' for users with an option to export to csv.
Users Login Monitor
users-login-monitor
A freeware plugin, for daily-notify site administrator, about users who logged in during the day.
userlog Developer Profile
1 plugin · 10 total installs
How We Detect userlog
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
window.alert