
WP Multisite User Sync/Unsync Security & Risk Analysis
wordpress.org/plugins/wp-multisite-user-syncSync/unsync users from one site (blog) to the other sites (blogs) in your WordPress Multisite Network.
Is WP Multisite User Sync/Unsync Safe to Use in 2026?
Generally Safe
Score 100/100WP Multisite User Sync/Unsync has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of wp-multisite-user-sync v1.5.0 reveals a plugin with a seemingly strong security posture in several key areas. The absence of dangerous functions, file operations, external HTTP requests, and the complete absence of any recorded vulnerabilities (CVEs) are positive indicators. Furthermore, all identified output operations are properly escaped, and there are no identified taint flows, suggesting that user input is handled securely to prevent common injection attacks. The zero-day attack surface from AJAX, REST API, shortcodes, and cron events without authentication checks is also a very good sign.
However, a significant concern arises from the presence of a single SQL query that does not utilize prepared statements. While the query count is low, the lack of prepared statements for any SQL query is a potential risk that could lead to SQL injection vulnerabilities if the input used within that query is not meticulously sanitized and validated elsewhere. The complete lack of nonce checks and capability checks across any entry points, even though the attack surface is currently reported as zero, suggests a potential weakness if new entry points were to be introduced or discovered without proper security considerations. The vulnerability history being completely clear is reassuring, but it's important to note that this doesn't negate the risks identified in the code analysis itself.
In conclusion, the plugin demonstrates good practices in output escaping and avoids common plugin vulnerabilities like dangerous functions and external requests. The major weakness lies in the un-prepared SQL query. The absence of checks like nonces and capabilities across potential (even if currently non-existent) entry points is also a concern that could be addressed proactively. The clean vulnerability history is a positive but should be viewed in conjunction with the identified code-level risks.
Key Concerns
- Raw SQL query without prepared statements
- Lack of nonce checks on potential entry points
- Lack of capability checks on potential entry points
WP Multisite User Sync/Unsync Security Vulnerabilities
WP Multisite User Sync/Unsync Release Timeline
WP Multisite User Sync/Unsync Code Analysis
SQL Query Safety
Output Escaping
WP Multisite User Sync/Unsync Attack Surface
WordPress Hooks 6
Maintenance & Trust
WP Multisite User Sync/Unsync Maintenance & Trust
Maintenance Signals
Community Trust
WP Multisite User Sync/Unsync Alternatives
Multisite User Sync
multisite-user-sync
Multisite User Sync will automatically synchronize users to all sites in multisite. Roles of users will be same on everysite.
Content Sync Assistant
content-sync-assistant
EN: Efficiently and reliably synchronize content between multiple WordPress sites. ZH: 高效可靠地在多个 WordPress 站点之间同步内容。
Publish Duplicate Post to Multisite
duplicate-publish-multisite
Duplicates a post and publish in a subsite from multisite. Syncs Posts from Categories between sites.
Members Multisite User Roles Sync
members-multisite-user-roles-sync
This is a simple Multisite add-on for Justin Tadlock's Members plugin, which synchronizes user (multiple) roles on all network sites.
Multisite sync for WooCommerce
multisite-sync-for-woocommerce
WooCommerce Multisite module to synchronize product data using the SKU (stock, price...)
WP Multisite User Sync/Unsync Developer Profile
2 plugins · 2K total installs
How We Detect WP Multisite User Sync/Unsync
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-multisite-user-sync/assets/js/wmus-script.js/wp-content/plugins/wp-multisite-user-sync/assets/js/wmus-script.jsHTML / DOM Fingerprints
wmus-check-uncheckwmus-sites