Advanced User Avatar | Custom Profile Picture Uploader for WordPress, WooCommerce, and BuddyPress Security & Risk Analysis
wordpress.org/plugins/wpmake-advance-user-avatarAdds an avatar upload field through a simple shortcode or block to let your site users upload a custom profile picture (avatar) directly from their de …
Is Advanced User Avatar | Custom Profile Picture Uploader for WordPress, WooCommerce, and BuddyPress Safe to Use in 2026?
Generally Safe
Score 100/100Advanced User Avatar | Custom Profile Picture Uploader for WordPress, WooCommerce, and BuddyPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wpmake-advance-user-avatar" v1.1.2 demonstrates a generally strong security posture based on the provided static analysis. The absence of any identified CVEs and the lack of critical or high-severity findings in taint analysis are significant strengths, suggesting a history of secure development and maintenance. The code also exhibits good practices such as 100% use of prepared statements for SQL queries and a high percentage of properly escaped output (92%). The presence of nonce and capability checks further indicates an awareness of common WordPress security vulnerabilities.
However, there are minor areas for improvement. While the overall attack surface is zero, the single file operation is not detailed, which could potentially be a vector if not handled with extreme care. The bundled Select2 library, while common, should be monitored for known vulnerabilities. Despite the high percentage of escaped output, the remaining 8% is a small but present risk for cross-site scripting (XSS) vulnerabilities if sensitive data is not consistently sanitized.
In conclusion, this plugin appears to be relatively secure with no glaring vulnerabilities identified in the static analysis or vulnerability history. The developers have implemented several key security measures. Continued vigilance regarding potential vulnerabilities in bundled libraries and ensuring 100% output escaping for all data types would further strengthen its security profile.
Key Concerns
- Potential risk with file operations
- Bundled library (Select2) may have vulnerabilities
- 8% of output not properly escaped
Advanced User Avatar | Custom Profile Picture Uploader for WordPress, WooCommerce, and BuddyPress Security Vulnerabilities
Advanced User Avatar | Custom Profile Picture Uploader for WordPress, WooCommerce, and BuddyPress Code Analysis
Bundled Libraries
Output Escaping
Advanced User Avatar | Custom Profile Picture Uploader for WordPress, WooCommerce, and BuddyPress Attack Surface
WordPress Hooks 17
Maintenance & Trust
Advanced User Avatar | Custom Profile Picture Uploader for WordPress, WooCommerce, and BuddyPress Maintenance & Trust
Maintenance Signals
Community Trust
Advanced User Avatar | Custom Profile Picture Uploader for WordPress, WooCommerce, and BuddyPress Alternatives
Custom Profile Picture – Replace Gravatar with Your Own Images
custom-profile-picture
Replace default Gravatars with custom profile pictures! Upload from media library or device. Bulk manage all users from one beautiful admin page.
WP Custom Avatar
wp-custom-avatar
WP Custom Avatar adds the capability to change the default Avatar in your website.
Letter Avatars
letter-avatars
Sets custom avatars for users without gravatar. Avatars will be replaced by first letter of usename (or e-mail) on a colorful background
AP Gravatars
ap-gravatars
A simple plugin that adds the gravatar photo associated with the user's email to their profile page... MultiSite compatable!
GITST CUSTOM AVATAR
gitst-custom-avatar-user-profile-pictures-manager
Set custom AVATAR (User Profile Image) and store avatars into Database as base64 string.
Advanced User Avatar | Custom Profile Picture Uploader for WordPress, WooCommerce, and BuddyPress Developer Profile
2 plugins · 200 total installs
How We Detect Advanced User Avatar | Custom Profile Picture Uploader for WordPress, WooCommerce, and BuddyPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpmake-advance-user-avatar/assets/js/admin/wpmake-advance-user-avatar-admin.js/wp-content/plugins/wpmake-advance-user-avatar/assets/js/select2/select2.min.js/wp-content/plugins/wpmake-advance-user-avatar/assets/css/select2/select2.css/wp-content/plugins/wpmake-advance-user-avatar/assets/css/wpmake-advance-user-avatar-admin.css/wp-content/plugins/wpmake-advance-user-avatar/assets/js/admin/wpmake-advance-user-avatar-admin.js/wp-content/plugins/wpmake-advance-user-avatar/assets/js/select2/select2.min.jswpmake-advance-user-avatar/assets/js/admin/wpmake-advance-user-avatar-admin.js?ver=wpmake-advance-user-avatar/assets/js/select2/select2.min.js?ver=wpmake-advance-user-avatar/assets/css/select2/select2.css?ver=wpmake-advance-user-avatar/assets/css/wpmake-advance-user-avatar-admin.css?ver=HTML / DOM Fingerprints
wpmake_aua_admin_params