
Username Security & Risk Analysis
wordpress.org/plugins/usernameThe Username plugin helps to change username, only if username is not exist and without effecting others user's username.
Is Username Safe to Use in 2026?
Generally Safe
Score 92/100Username has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "username" v1.3 plugin exhibits a mixed security posture, with some strengths but significant concerning weaknesses. While the absence of dangerous functions, SQL injection risks due to prepared statements, file operations, external requests, and known CVEs is positive, the plugin has a critical vulnerability stemming from its attack surface. There is one AJAX handler, and crucially, it lacks any authentication checks. This represents a direct entry point for malicious actors to interact with the plugin's functionality without proper authorization, potentially leading to unintended actions or data exposure. The vulnerability history is clean, which is good, but this does not mitigate the immediate risk posed by the unprotected AJAX endpoint. The lack of output escaping is also a notable concern, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities when data is displayed to users. Overall, while the plugin avoids common pitfalls, the unprotected AJAX handler is a severe flaw that requires immediate attention.
Key Concerns
- Unprotected AJAX handler
- Unescaped output
Username Security Vulnerabilities
Username Code Analysis
Output Escaping
Username Attack Surface
AJAX Handlers 1
WordPress Hooks 3
Maintenance & Trust
Username Maintenance & Trust
Maintenance Signals
Community Trust
Username Alternatives
Easy Username Updater
username-updater
A plugin to change registered username and display name.
Admin Credentials Editor
admin-credentials-editor
Easily change your admin credentials (username, email, password) from the dashboard.
Loginizer
loginizer
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Redux Framework
redux-framework
Redux is a simple, truly extensible, and fully responsive options framework for WordPress themes and plugins. It ships with an integrated demo.
LightStart – Maintenance Mode, Coming Soon and Landing Page Builder
wp-maintenance-mode
Easy Drag & Drop Page Builder that adds a splash page to your site that it's perfect for a coming soon page, maintenance or landing page.
Username Developer Profile
3 plugins · 1K total installs
How We Detect Username
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/username/js/username.jsusername/js/username.jsHTML / DOM Fingerprints
clickmeid="clickme"id="username-use"