Users manager – PN Security & Risk Analysis

wordpress.org/plugins/userspn

Streamline user management on your WordPress site with this powerful plugin. Enable custom forms, secure login, and seamless profile management.

0 active installs v1.1.30 PHP 7.2+ WP 3.0.1+ Updated Apr 15, 2026
contactsloginregisteruser-managementusers
94
A · Safe
CVEs total1
Unpatched0
Last CVEApr 7, 2026
Safety Verdict

Is Users manager – PN Safe to Use in 2026?

Generally Safe

Score 94/100

Users manager – PN has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Apr 7, 2026Updated 1mo ago
Risk Assessment

The 'userspn' plugin version 1.1.15 demonstrates a generally strong security posture based on the static analysis. The absence of direct entry points like AJAX handlers, REST API routes, and shortcodes significantly limits the immediate attack surface. Furthermore, the code exhibits good practices with a high percentage of SQL queries using prepared statements and a large majority of output operations being properly escaped. The presence of nonce and capability checks further bolsters its defensive mechanisms.

Despite these strengths, there are a few areas of concern. The taint analysis revealed three flows with unsanitized paths, although they were not categorized as critical or high severity. This indicates a potential for subtle vulnerabilities that might not be immediately obvious. The plugin also makes one external HTTP request, which, depending on its implementation, could be a vector for supply chain attacks or cross-site scripting if not handled securely. The bundled DataTables library, while common, could be a concern if it's an outdated version, as this is a frequent source of vulnerabilities.

The plugin's vulnerability history is remarkably clean, with zero known CVEs. This suggests a history of responsible development and maintenance, or that the plugin hasn't been a significant target for vulnerability research. In conclusion, 'userspn' v1.1.15 is reasonably secure, with a robust approach to common WordPress security pitfalls. However, the unsanitized paths in taint analysis and the potential risk associated with the bundled library warrant careful consideration and potential further investigation.

Key Concerns

  • Flows with unsanitized paths found
  • External HTTP requests present
  • Bundled library DataTables present
Vulnerabilities
1 published

Users manager – PN Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Critical
1

1 total CVE

CVE-2026-4003critical · 9.8Missing Authorization

Users manager – PN <= 1.1.15 - Unauthenticated Privilege Escalation via Account Takeover via 'userspn_form_save' AJAX Action

Apr 7, 2026 Patched in 1.1.20 (1d)
Version History

Users manager – PN Release Timeline

v1.1.30Current
v1.1.25
v1.1.20
v1.1.151 CVE
v1.1.91 CVE
v1.1.71 CVE
v1.0.311 CVE
v1.0.291 CVE
v1.0.271 CVE
v1.0.171 CVE
v1.0.151 CVE
v1.0.131 CVE
v1.0.61 CVE
v1.0.31 CVE
v1.0.21 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 17, 2026

Users manager – PN Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
10 prepared
Unescaped Output
100
833 escaped
Nonce Checks
8
Capability Checks
26
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

DataTables

SQL Query Safety

83% prepared12 total queries

Output Escaping

89% escaped933 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

7 flows3 with unsanitized paths
userspn_ajax_server (includes\class-userspn-ajax.php:19)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Users manager – PN Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterrender_blockincludes\class-userspn-blocks.php:65
actionwp_enqueue_scriptsincludes\class-userspn-selector.php:29
actionadmin_enqueue_scriptsincludes\class-userspn-selector.php:30
actioninituserspn.php:204

Scheduled Events 2

userspn_cron_daily
userspn_cron_thirty_minutes
Maintenance & Trust

Users manager – PN Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 15, 2026
PHP min version7.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Users manager – PN Developer Profile

Félix Martínez

8 plugins · 20 total installs

99
trust score
Avg Security Score
98/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Users manager – PN

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/userspn/assets/css/admin/userspn-admin.css/wp-content/plugins/userspn/assets/js/admin/userspn-admin.js
Script Paths
/wp-content/plugins/userspn/assets/js/admin/userspn-admin.js
Version Parameters
userspn-admin?ver=userspn-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
userspn-admin-wrap
Data Attributes
data-userspn-metadata-userspn-popup-iddata-userspn-post-iddata-userspn-parentdata-userspn-parent-optiondata-userspn-type+6 more
JS Globals
USERSPN_VERSIONUSERSPN_DIRUSERSPN_URL
FAQ

Frequently Asked Questions about Users manager – PN