
WP Frontend Profile Security & Risk Analysis
wordpress.org/plugins/wp-front-end-profileWP Frontend Profile allows users to edit/view their profile and register/login without going into the dashboard to do so.
Is WP Frontend Profile Safe to Use in 2026?
Mostly Safe
Score 83/100WP Frontend Profile is generally safe to use. 5 past CVEs were resolved. Keep it updated.
The wp-front-end-profile plugin exhibits a mixed security posture. While it demonstrates strong adherence to secure coding practices with 100% of SQL queries using prepared statements and a high percentage of output being properly escaped, there are significant areas of concern. The taint analysis reveals two high-severity flows with unsanitized paths, indicating potential vulnerabilities where user-supplied data could be manipulated to execute unintended actions or access sensitive information. Furthermore, the plugin's history of 5 known CVEs, including 2 critical and 1 high severity, spanning various common vulnerability types like CSRF, missing authorization, XSS, and privilege management, suggests a recurring pattern of security weaknesses. Although no currently unpatched vulnerabilities are listed and recent security measures like nonce and capability checks are present, the historical trend and high-severity taint flows warrant caution. The plugin's strengths lie in its robust handling of SQL and output escaping, but the presence of unsanitized paths and a history of critical vulnerabilities present a notable risk.
Key Concerns
- High severity unsanitized taint flows
- History of 2 critical CVEs
- History of 1 high CVE
- Bundled outdated Freemius v1.0
WP Frontend Profile Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
WP Frontend Profile <= 1.3.8 - Cross-Site Request Forgery to Unauthorized User Account Approval or Rejection
WP Frontend Profile <= 1.3.1 - Unauthenticated Privilege Escalation
WP Frontend Profile <= 1.2.1 - Cross-Site Request Forgery
WP Front End Profile <= 0.2.1 - Stored Cross-Site Scripting
WP Front End Profile <= 0.2.1 - Privilege Escalation
WP Frontend Profile Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Frontend Profile Attack Surface
AJAX Handlers 5
Shortcodes 4
WordPress Hooks 78
Maintenance & Trust
WP Frontend Profile Maintenance & Trust
Maintenance Signals
Community Trust
WP Frontend Profile Alternatives
Login Logout Menu
login-logout-menu
Login Logout Menu is a handy plugin which allows you to add login, logout, register and profile menu items in your selected menu.
JSON API User
json-api-user
Extends the JSON API Plugin to allow RESTful user registration, authentication & many other User Meta, BP functions. A Pro version is also available.
Frontend Dashboard
frontend-dashboard
Frontend Dashboard is bundled with huge list of custom features which can easily customise the User profile, Posts, Login, Register, Custom roles.
BP XProfile Shortcode
bp-xprofile-shortcode
Adds Shortcode for BuddyPress XProfile data
Multibyte CAPTCHA login and Mail only register
user-mail-only-register
Multibyte CAPTCHA login form and register users with mail only.
WP Frontend Profile Developer Profile
1 plugin · 100 total installs
How We Detect WP Frontend Profile
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-front-end-profile/assets/css/wpfep-admin-style.css/wp-content/plugins/wp-front-end-profile/assets/js/admin.js/wp-content/plugins/wp-front-end-profile/assets/js/settings.js/wp-content/plugins/wp-front-end-profile/freemius/start.phpwp-front-end-profile/assets/css/wpfep-admin-style.css?ver=wp-front-end-profile/assets/js/admin.js?ver=wp-front-end-profile/assets/js/settings.js?ver=HTML / DOM Fingerprints
wpfep-admin-styledata-wpfep-idwfep_fswpfep_admin_params