Users manager – PN Security & Risk Analysis

wordpress.org/plugins/userspn

Streamline user management on your WordPress site with this powerful plugin. Enable custom forms, secure login, and seamless profile management.

0 active installs v1.1.15 PHP 7.2+ WP 3.0.1+ Updated Mar 5, 2026
contactsloginregisteruser-managementusers
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Users manager – PN Safe to Use in 2026?

Generally Safe

Score 100/100

Users manager – PN has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'userspn' plugin version 1.1.15 demonstrates a generally strong security posture based on the static analysis. The absence of direct entry points like AJAX handlers, REST API routes, and shortcodes significantly limits the immediate attack surface. Furthermore, the code exhibits good practices with a high percentage of SQL queries using prepared statements and a large majority of output operations being properly escaped. The presence of nonce and capability checks further bolsters its defensive mechanisms.

Despite these strengths, there are a few areas of concern. The taint analysis revealed three flows with unsanitized paths, although they were not categorized as critical or high severity. This indicates a potential for subtle vulnerabilities that might not be immediately obvious. The plugin also makes one external HTTP request, which, depending on its implementation, could be a vector for supply chain attacks or cross-site scripting if not handled securely. The bundled DataTables library, while common, could be a concern if it's an outdated version, as this is a frequent source of vulnerabilities.

The plugin's vulnerability history is remarkably clean, with zero known CVEs. This suggests a history of responsible development and maintenance, or that the plugin hasn't been a significant target for vulnerability research. In conclusion, 'userspn' v1.1.15 is reasonably secure, with a robust approach to common WordPress security pitfalls. However, the unsanitized paths in taint analysis and the potential risk associated with the bundled library warrant careful consideration and potential further investigation.

Key Concerns

  • Flows with unsanitized paths found
  • External HTTP requests present
  • Bundled library DataTables present
Vulnerabilities
None known

Users manager – PN Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Users manager – PN Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
10 prepared
Unescaped Output
100
833 escaped
Nonce Checks
8
Capability Checks
26
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

DataTables

SQL Query Safety

83% prepared12 total queries

Output Escaping

89% escaped933 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

7 flows3 with unsanitized paths
userspn_ajax_server (includes\class-userspn-ajax.php:19)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Users manager – PN Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterrender_blockincludes\class-userspn-blocks.php:65
actionwp_enqueue_scriptsincludes\class-userspn-selector.php:29
actionadmin_enqueue_scriptsincludes\class-userspn-selector.php:30
actioninituserspn.php:204

Scheduled Events 2

userspn_cron_daily
userspn_cron_thirty_minutes
Maintenance & Trust

Users manager – PN Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMar 5, 2026
PHP min version7.2
Downloads845

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Users manager – PN Developer Profile

Félix Martínez

8 plugins · 20 total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Users manager – PN

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/userspn/assets/css/admin/userspn-admin.css/wp-content/plugins/userspn/assets/js/admin/userspn-admin.js
Script Paths
/wp-content/plugins/userspn/assets/js/admin/userspn-admin.js
Version Parameters
userspn-admin?ver=userspn-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
userspn-admin-wrap
Data Attributes
data-userspn-metadata-userspn-popup-iddata-userspn-post-iddata-userspn-parentdata-userspn-parent-optiondata-userspn-type+6 more
JS Globals
USERSPN_VERSIONUSERSPN_DIRUSERSPN_URL
FAQ

Frequently Asked Questions about Users manager – PN