WP User Profile Restriction Security & Risk Analysis

wordpress.org/plugins/wp-user-profile-restriction

Restrict user profile editing with granular role-based controls, custom redirects, and automatic menu hiding for enhanced WordPress security.

400 active installs v2.0.0 PHP + WP 4.0.3+ Updated Nov 10, 2025
disable-editing-user-profiledisable-updating-my-profilemy-profile-restrictionprofile-php-restrictionuser-profile-restriction
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP User Profile Restriction Safe to Use in 2026?

Generally Safe

Score 100/100

WP User Profile Restriction has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "wp-user-profile-restriction" v2.0.0 plugin exhibits a generally good security posture based on the provided static analysis. There are no identified vulnerabilities in its history, no dangerous functions, no external HTTP requests, and no file operations, which are all positive indicators. The use of prepared statements for SQL queries is excellent, and the presence of capability checks is a basic security control. However, the lack of nonce checks and the relatively low percentage (56%) of properly escaped output are areas of concern. While the attack surface appears minimal with zero entry points, this could also indicate limited functionality, making it difficult to fully assess its security in a real-world context. The absence of taint analysis results also prevents a thorough examination of data flow vulnerabilities.

Despite the absence of known vulnerabilities and a seemingly limited attack surface, the 56% output escaping rate suggests potential for Cross-Site Scripting (XSS) vulnerabilities. The lack of nonce checks, while not directly tied to an exposed entry point in this analysis, is a missed security best practice that could become an issue if functionality changes or is extended without proper security considerations. The plugin's history of zero vulnerabilities is a strong positive, but it's crucial to remember that a lack of historical issues doesn't guarantee future security, especially with observed weaknesses in output handling. Overall, the plugin appears to be on solid ground regarding core security principles, but attention to output escaping and nonces would significantly strengthen its security.

Key Concerns

  • Output escaping is only 56% proper
  • Missing nonce checks
Vulnerabilities
None known

WP User Profile Restriction Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP User Profile Restriction Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
9 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

56% escaped16 total outputs
Attack Surface

WP User Profile Restriction Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_initwp-upr.php:36
actionadmin_menuwp-upr.php:37
actionload-profile.phpwp-upr.php:38
Maintenance & Trust

WP User Profile Restriction Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 10, 2025
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings5
Active installs400
Alternatives

WP User Profile Restriction Alternatives

No alternatives data available yet.

Developer Profile

WP User Profile Restriction Developer Profile

Shawon C.

2 plugins · 410 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP User Profile Restriction

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-user-profile-restriction/css/style.css/wp-content/plugins/wp-user-profile-restriction/js/admin.js
Script Paths
/wp-content/plugins/wp-user-profile-restriction/js/admin.js
Version Parameters
wp-user-profile-restriction/css/style.css?ver=wp-user-profile-restriction/js/admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP User Profile Restriction