{"id":352428,"date":"2026-08-24T17:43:19","date_gmt":"2026-08-24T17:43:19","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/ethwebs-role-auditor\/"},"modified":"2026-08-24T17:42:42","modified_gmt":"2026-08-24T17:42:42","slug":"ethwebs-role-auditor","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/ethwebs-role-auditor\/","author":16152665,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.1","stable_tag":"1.0.1","tested":"7.1","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"Ethwebs Role Auditor","header_author":"Sanmatiraj","header_description":"Lightweight, zero-bloat security auditor that monitors user roles, catches direct database SQL injection admin additions, and displays on-screen and emailed security reports.","assets_banners_color":"","last_updated":"2026-08-24 17:42:42","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/wayanad.co.in\/wordpress-plugins\/","header_plugin_uri":"","header_author_uri":"https:\/\/wayanad.co.in","rating":0,"author_block_rating":0,"active_installs":0,"downloads":53,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"sanmathiraj","date":"2026-08-15 08:04:56"},"1.0.1":{"tag":"1.0.1","author":"sanmathiraj","date":"2026-08-24 17:42:42"}},"upgrade_notice":{"1.0.1":"<p>Upgrade to version 1.0.1 for live database role counts in settings, dynamic email subject preview lines, and persistent IP access tracking.<\/p>"},"ratings":[],"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.0.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3648222,"resolution":"1","location":"assets","locale":"","width":660,"height":453},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3648222,"resolution":"2","location":"assets","locale":"","width":715,"height":160},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3648222,"resolution":"3","location":"assets","locale":"","width":896,"height":332},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3648222,"resolution":"4","location":"assets","locale":"","width":755,"height":325},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3648222,"resolution":"5","location":"assets","locale":"","width":497,"height":196}},"screenshots":{"1":"Current Role Status: Live database audit table showing user counts per role and detected active admin user IDs.","2":"Manual Audit &amp; Email Trigger: Instant on-demand audit trigger button and email dispatch status notice.","3":"Configuration Settings: Notification email recipients, maximum expected admins baseline, and alert option checkboxes.","4":"Setup Email Report: Sample security audit report email received with live user role summary and subject line count preview.","5":"Admin IP Access Alert: Security email intimation received when an administrator accesses the dashboard from a new IP address."}},"plugin_section":[],"plugin_tags":[83,8533,153,1915,600],"plugin_category":[54],"plugin_contributors":[272158],"plugin_business_model":[],"class_list":["post-352428","plugin","type-plugin","status-publish","hentry","plugin_tags-admin","plugin_tags-audit","plugin_tags-database","plugin_tags-roles","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-sanmathiraj","plugin_committers-sanmathiraj"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/ethwebs-role-auditor.svg","icon_2x":false,"generated":true},"screenshots":[{"src":"https:\/\/ps.w.org\/ethwebs-role-auditor\/assets\/screenshot-1.png?rev=3648222","caption":"Current Role Status: Live database audit table showing user counts per role and detected active admin user IDs."},{"src":"https:\/\/ps.w.org\/ethwebs-role-auditor\/assets\/screenshot-2.png?rev=3648222","caption":"Manual Audit &amp; Email Trigger: Instant on-demand audit trigger button and email dispatch status notice."},{"src":"https:\/\/ps.w.org\/ethwebs-role-auditor\/assets\/screenshot-3.png?rev=3648222","caption":"Configuration Settings: Notification email recipients, maximum expected admins baseline, and alert option checkboxes."},{"src":"https:\/\/ps.w.org\/ethwebs-role-auditor\/assets\/screenshot-4.png?rev=3648222","caption":"Setup Email Report: Sample security audit report email received with live user role summary and subject line count preview."},{"src":"https:\/\/ps.w.org\/ethwebs-role-auditor\/assets\/screenshot-5.png?rev=3648222","caption":"Admin IP Access Alert: Security email intimation received when an administrator accesses the dashboard from a new IP address."}],"raw_content":"<!--section=description-->\n<p><strong>Ethwebs Role Auditor<\/strong> is an ultra-lightweight, zero-bloat security tool specifically built to catch privilege escalation and unauthorized administrator account creations\u2014even when performed via direct database SQL injection attacks that bypass standard security plugins.<\/p>\n\n<p>Most security logging plugins create heavy custom database tables and rely strictly on standard WordPress hooks (<code>wp_login<\/code>, <code>user_register<\/code>). When attackers exploit database vulnerabilities, they insert rows directly into <code>wp_users<\/code> and <code>wp_usermeta<\/code>, bypassing WordPress hooks entirely.<\/p>\n\n<p>Ethwebs Role Auditor addresses this by running direct, prefix-aware SQL database queries during scheduled background audits to count and identify every single user account holding administrator capabilities.<\/p>\n\n<h3>Key Features:<\/h3>\n\n<ul>\n<li><strong>Direct Database SQL Audit:<\/strong> Queries the database directly to detect unauthorized administrator accounts added via SQL injection.<\/li>\n<li><strong>Instant Dashboard Status:<\/strong> Displays real-time role counts and active admin IDs immediately upon opening the settings page.<\/li>\n<li><strong>Smart Subject Line Previews:<\/strong> View current admin and editor counts directly in your email inbox subject line without having to open the message.<\/li>\n<li><strong>Multiple Recipient Notifications:<\/strong> Enter single or comma-separated email addresses to notify your security team.<\/li>\n<li><strong>Attacker Exclusion Protection:<\/strong> Intelligently strips newly promoted\/attacker email addresses from receiving security alerts.<\/li>\n<li><strong>Manual \"Run Check Now\" Audit:<\/strong> Trigger an instant on-demand database scan and email test directly from your settings panel.<\/li>\n<li><strong>Instant Role Elevation Alerts:<\/strong> Receive email notifications whenever a user is created or promoted to Administrator or Editor.<\/li>\n<li><strong>New Admin Login IP Detection:<\/strong> Lightweight persistent IP tracking notifies you when an administrator accesses the dashboard from an unrecognized IP address.<\/li>\n<li><strong>Zero Database Bloat:<\/strong> Creates zero custom database tables and runs cleanly in the background.<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>ethwebs-role-auditor<\/code> folder to the <code>\/wp-content\/plugins\/<\/code> directory.<\/li>\n<li>Activate the plugin through the <strong>Plugins<\/strong> menu in WordPress.<\/li>\n<li>Navigate to <strong>Settings &gt; Ethwebs Role Auditor<\/strong> to configure recipient emails and alert preferences.<\/li>\n<li>Click <strong>Run Check Now &amp; Send Email<\/strong> to send an instant email report copy.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20an%20smtp%20plugin%20configured%20for%20this%20plugin%20to%20work%3F\"><h3>Do I need an SMTP plugin configured for this plugin to work?<\/h3><\/dt>\n<dd><p>No. While email reports are sent out in the background, the settings page inside the WordPress dashboard always displays the full, real-time audit table (including user role counts and active admin user IDs) directly on screen.<\/p><\/dd>\n<dt id=\"how%20does%20this%20plugin%20detect%20attacks%20that%20bypass%20standard%20security%20plugins%3F\"><h3>How does this plugin detect attacks that bypass standard security plugins?<\/h3><\/dt>\n<dd><p>Most security plugins rely strictly on standard WordPress action hooks (like <code>wp_login<\/code>). When attackers use SQL injection vulnerabilities, they write administrative users directly into database tables (<code>wp_users<\/code> and <code>wp_usermeta<\/code>), completely bypassing the WordPress hook layer. Ethwebs Role Auditor executes a direct SQL database query against your actual database table prefix to count and identify every single user account holding <code>administrator<\/code> capabilities, catching silent database modifications instantly.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20an%20attacker%20creates%20an%20admin%20account%20with%20their%20own%20email%20address%3F\"><h3>What happens if an attacker creates an admin account with their own email address?<\/h3><\/dt>\n<dd><p>Ethwebs Role Auditor features an Attacker Exclusion Safeguard. When an instant role elevation alert fires, the plugin checks the promoted user's email address against your notification list and strips out the attacker's email, ensuring they never receive security warnings about their own activity.<\/p><\/dd>\n<dt id=\"can%20i%20send%20alerts%20to%20multiple%20team%20members%3F\"><h3>Can I send alerts to multiple team members?<\/h3><\/dt>\n<dd><p>Yes. You can enter multiple comma-separated email addresses (e.g. <code>admin@site.com, security@site.com<\/code>) in the Notification Email field under <strong>Settings &gt; Ethwebs Role Auditor<\/strong>.<\/p><\/dd>\n<dt id=\"will%20this%20plugin%20slow%20down%20my%20site%20or%20bloat%20my%20database%3F\"><h3>Will this plugin slow down my site or bloat my database?<\/h3><\/dt>\n<dd><p>No. Unlike standard activity log plugins that write thousands of rows to your database every time a page is loaded, Ethwebs Role Auditor is zero-bloat. It creates zero custom database tables. Cron checks run lightly in the background once per day, and temporary session IP tracking uses standard auto-expiring WordPress transients.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Added dynamic email subject lines showing live admin and editor counts directly in inbox previews.<\/li>\n<li>Enhanced settings page to display live database role counts and active admin IDs immediately on page load.<\/li>\n<li>Upgraded IP tracking to persistent user meta whitelisting to catch backdoor dashboard access without email spam on clicks.<\/li>\n<li>Added detailed UI and email sample screenshots to directory listing.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release. Features direct database auditing, on-screen dashboard report displays, comma-separated multiple email recipients, attacker exclusion safeguard, manual audit check trigger, and IP tracking.<\/li>\n<\/ul>","raw_excerpt":"Lightweight security auditor monitoring user roles, catching direct database admin additions, and sending instant security alerts.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/352428","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=352428"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/sanmathiraj"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=352428"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=352428"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=352428"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=352428"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=352428"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=352428"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}