

Riskora User Scanner dashboard and scan controls
Riskora User Scanner helps site administrators identify suspicious users, fake accounts, spam-like registrations, and inactive accounts.
The plugin calculates an advisory risk score for each user based on signals such as temporary email domains, suspicious usernames, incomplete profiles, missing activity, and login data collected after plugin activation.
The score is intended to support careful manual review. It is not proof that an account is malicious, and the plugin never deletes users automatically.
The plugin does not automatically delete or block users.
Authorized administrators must review accounts manually before taking action. A risk score is only an indicator and may include false positives.
Administrator protection is enabled by default. Disabling this protection should be done only after carefully reviewing the possible consequences.
User deletion is permanent. Create a database backup before deleting user accounts from a production site, especially before using bulk deletion.
Riskora User Scanner processes WordPress user account information locally to calculate risk scores and help authorized administrators review suspicious accounts.
The plugin does not transmit user account data, risk scores, scan results, or plugin logs to external services.
During analysis, the plugin may read user IDs, usernames, email addresses, roles, registration dates, profile data, and activity indicators already stored by WordPress.
The plugin may store:
When a user is deleted through the plugin, the username and email address may remain in an activity log until that log entry reaches the configured retention period.
Logs are automatically removed according to the configured retention period.
Plugin data is retained during uninstall by default. Administrators can enable complete data removal in the plugin settings before uninstalling.
Suggested privacy policy text is available in the WordPress Privacy Policy Guide.