
WPMU Blog Name Restrictions Override Security & Risk Analysis
wordpress.org/plugins/wpmu-blog-name-restrictions-overrideThis plugin provides a way for site admins to allow blog creators more options for blog name (less restrictive than built-in defaults).
Is WPMU Blog Name Restrictions Override Safe to Use in 2026?
Generally Safe
Score 85/100WPMU Blog Name Restrictions Override has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wpmu-blog-name-restrictions-override" v2.0 exhibits a generally good security posture in terms of its attack surface and data handling, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events. The absence of known vulnerabilities in its history is also a positive indicator. However, the static analysis reveals significant concerns that detract from its overall safety. The presence of the `create_function` function is a critical red flag, as it's deprecated and can be a vector for code injection if used with user-supplied input, although the analysis does not show any explicit taint flows originating from it. Furthermore, the complete lack of output escaping is highly problematic, meaning any content rendered by the plugin could be vulnerable to cross-site scripting (XSS) attacks if it incorporates any dynamic data. The absence of nonce and capability checks, while not directly exploitable due to the limited attack surface, indicates a lack of robust security practices in general. While the plugin appears to handle SQL queries securely and has no external dependencies, the use of `create_function` and the complete failure to escape output represent substantial risks.
Key Concerns
- Dangerous function used (create_function)
- 100% of outputs are not properly escaped
- 0 Nonce checks
- 0 Capability checks
WPMU Blog Name Restrictions Override Security Vulnerabilities
WPMU Blog Name Restrictions Override Code Analysis
Dangerous Functions Found
Output Escaping
WPMU Blog Name Restrictions Override Attack Surface
WordPress Hooks 4
Maintenance & Trust
WPMU Blog Name Restrictions Override Maintenance & Trust
Maintenance Signals
Community Trust
WPMU Blog Name Restrictions Override Alternatives
Admin Menu Editor
admin-menu-editor
Lets you edit the WordPress admin menu. You can re-order, hide or rename menus, add custom menus and more.
Disable User Gravatar
disable-user-gravatar
Stops WordPress from grabbing a user avatar using their registrated email from gravatar.com.
BP Disable Activation Reloaded
bp-disable-activation-reloaded
Based on crashutah, apeatling plugin Disables the activation email and automatically activates new users in BuddyPress under a standard WP install and …
Advanced Export for WP & WPMU
advanced-export-for-wp-wpmu
Adds an Advanced Export to the Tools menu which allows selective exporting of pages, posts, specific categories and/or post statuses by date.
Activate Update Services
activate-update-services
WordPress removes the Update Services ability when you create a network. Activate this plugin to get it back.
WPMU Blog Name Restrictions Override Developer Profile
7 plugins · 70 total installs
How We Detect WPMU Blog Name Restrictions Override
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
cets_bnro_allowdashescets_bnro_allowunderscorescets_bnro_allownumericcets_bnro_allowuppercets_bnro_minlengthname="cets_bnro_allowdashes"id="cets_bnro_allowdashes"name="cets_bnro_allowunderscores"id="cets_bnro_allowunderscores"name="cets_bnro_allownumeric"id="cets_bnro_allownumeric"+4 more