When Last Login – Export User Records Security & Risk Analysis

wordpress.org/plugins/when-last-login-export-user-records

Export your user's login records into a CSV or JSON file in seconds.

600 active installs v1.1 PHP + WP 5.0+ Updated Feb 3, 2026
export-user-login-recordslast-loginuser-login-recordswhen-last-login
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is When Last Login – Export User Records Safe to Use in 2026?

Generally Safe

Score 100/100

When Last Login – Export User Records has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The 'when-last-login-export-user-records' plugin v1.1 exhibits a strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code signals indicate good security practices, with 100% of SQL queries using prepared statements, a respectable 70% of outputs being properly escaped, and the presence of nonce checks. The lack of dangerous functions, external HTTP requests, and the successful taint analysis showing no unsanitized flows further bolster its security. The plugin's vulnerability history is also clean, with no recorded CVEs, suggesting a track record of stable and secure development. However, the presence of file operations and zero capability checks, while not explicitly indicating a vulnerability in this version, represents potential areas that could become risky if the plugin's functionality evolves without appropriate access controls. Overall, this plugin appears to be very secure in its current state, with no immediate critical vulnerabilities identified. The primary areas for potential future concern would be around access control for file operations and ensuring ongoing adherence to output escaping best practices as the plugin is updated.

Key Concerns

  • File operations present
  • No capability checks
  • Output escaping not 100%
Vulnerabilities
None known

When Last Login – Export User Records Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

When Last Login – Export User Records Release Timeline

v1.1Current
v1.0.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

When Last Login – Export User Records Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
14 escaped
Nonce Checks
2
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

70% escaped20 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
wll_eur_export_records (when-last-login-export-user-records.php:64)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

When Last Login – Export User Records Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterwll_settings_page_tabswhen-last-login-export-user-records.php:27
filterwll_settings_page_contentwhen-last-login-export-user-records.php:28
actioninitwhen-last-login-export-user-records.php:29
actionadmin_menuwhen-last-login-export-user-records.php:30
Maintenance & Trust

When Last Login – Export User Records Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 3, 2026
PHP min version
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs600
Developer Profile

When Last Login – Export User Records Developer Profile

Andrew Lima

7 plugins · 66K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
388 days
View full developer profile
Detection Fingerprints

How We Detect When Last Login – Export User Records

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about When Last Login – Export User Records