
Who Is Online Now Security & Risk Analysis
wordpress.org/plugins/who-is-online-nowSee how many Visitor and Author's are online also how many from mobile device by this plugin. Its a Ajax based plugin.
Is Who Is Online Now Safe to Use in 2026?
Generally Safe
Score 85/100Who Is Online Now has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'who-is-online-now' v1.0.2 plugin exhibits several concerning security practices that significantly elevate its risk profile. The static analysis reveals a substantial attack surface with two AJAX handlers, both lacking authentication checks. This is a critical vulnerability as it allows any unauthenticated user to interact with these handlers, potentially triggering unintended actions or exposing sensitive information. Furthermore, the presence of a dangerous function like `create_function` is a red flag, often associated with code injection vulnerabilities. The low percentage of properly escaped output (20%) suggests that user-supplied data might be rendered directly into the HTML, opening the door to Cross-Site Scripting (XSS) attacks.
The plugin's vulnerability history is notably clean, with no recorded CVEs. While this might seem positive, it does not negate the risks identified in the code. A clean history can sometimes be misleading, especially for plugins that are not widely targeted or have not undergone extensive security audits. The lack of taint analysis results is also a point of concern, as it implies either the analysis tool could not effectively analyze the code or no obvious taint flows were detected, which doesn't necessarily mean the code is secure.
In conclusion, the 'who-is-online-now' v1.0.2 plugin has a poor security posture due to its unprotected entry points, use of dangerous functions, and inadequate output escaping. The absence of known vulnerabilities should not be interpreted as a guarantee of security, given the identified code-level weaknesses. These issues collectively present a significant risk to any WordPress site using this plugin.
Key Concerns
- Unprotected AJAX handlers
- Dangerous function detected (create_function)
- Low output escaping rate
- No nonce checks on AJAX
- No capability checks
- Low percentage of prepared SQL statements
Who Is Online Now Security Vulnerabilities
Who Is Online Now Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Who Is Online Now Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Who Is Online Now Maintenance & Trust
Maintenance Signals
Community Trust
Who Is Online Now Developer Profile
2 plugins · 80 total installs
How We Detect Who Is Online Now
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/who-is-online-now/inc/wpmwo_visitor.css/wp-content/plugins/who-is-online-now/inc/wpmwo_visitor.js/wp-content/plugins/who-is-online-now/inc/wpmwo_visitor.jswho-is-online-now/inc/wpmwo_visitor.css?ver=who-is-online-now/inc/wpmwo_visitor.js?ver=HTML / DOM Fingerprints
wpmwo_member_avatarwpmwo_member_namedata-avatar_sizedata-show_memberdata-member_styledata-hide_adminwpmwo_get_online_user_ajax<span id='mvtotalss'><span id='mvreguserss'><span id='mvmbuserss'><li class="wpmwo_member_avatar">