
User Box Security & Risk Analysis
wordpress.org/plugins/users-boxPlugin provides a widget for displaying avatars of registered users.
Is User Box Safe to Use in 2026?
Generally Safe
Score 85/100User Box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'users-box' plugin version 1.0.4 exhibits a mixed security posture. On the positive side, the plugin has a remarkably small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events that could be directly exploited. Furthermore, there is no recorded vulnerability history (CVEs), suggesting a history of stable and secure releases. However, the static code analysis reveals significant concerns. The presence of the `create_function` is a critical red flag, as it's deprecated and can be a source of severe security vulnerabilities, particularly if used with user-supplied input. Additionally, the plugin performs SQL queries without using prepared statements, which opens the door to SQL injection vulnerabilities. The low percentage of properly escaped output further exacerbates these risks, as it indicates a high likelihood of cross-site scripting (XSS) vulnerabilities. While the plugin has no known vulnerabilities historically, the immediate code-level risks are substantial.
Key Concerns
- Usage of deprecated and dangerous function create_function
- SQL queries not using prepared statements
- Low percentage of properly escaped output
- No nonce checks implemented
- No capability checks implemented
User Box Security Vulnerabilities
User Box Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
User Box Attack Surface
WordPress Hooks 2
Maintenance & Trust
User Box Maintenance & Trust
Maintenance Signals
Community Trust
User Box Alternatives
Starbox – the Author Box for Humans
starbox
Starbox is the Author Box for Humans. Professional Themes to choose from, HTML5, Social Media Profiles, Google Authorship
Team List
wp-team-list
Display your teammates anywhere on your WordPress site using this easy-to-use plugin.
Co-Authors Plus
co-authors-plus
Assign multiple bylines to posts, pages, and custom post types with a search-as-you-type input box.
WP-UserOnline
wp-useronline
Enable you to display how many users are online on your Wordpress blog with detailed statistics.
Smart User Slug Hider
smart-user-slug-hider
Hide usernames in Author Pages URLs to enhance Security
User Box Developer Profile
1 plugin · 10 total installs
How We Detect User Box
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/users-box/css/style.cssHTML / DOM Fingerprints
ubw-users-boxubw-userubw-shape-circleubw-shape-rectangleid="usersboxwidget"class="usersboxwidget"