Riskora User Scanner
Riskora User Scanner

Riskora User Scanner

0/5 (0 ratings) — active installs Updated Sep 23, 2026
Riskora User Scanner dashboard and scan controls

Riskora User Scanner dashboard and scan controls

Riskora User Scanner helps site administrators identify suspicious users, fake accounts, spam-like registrations, and inactive accounts.

The plugin calculates an advisory risk score for each user based on signals such as temporary email domains, suspicious usernames, incomplete profiles, missing activity, and login data collected after plugin activation.

The score is intended to support careful manual review. It is not proof that an account is malicious, and the plugin never deletes users automatically.

Main Features

  • Manual user scans with AJAX batch processing
  • Configurable scan batch size
  • Risk scores and risk levels: low, medium, high, and critical
  • Expandable full-width panel explaining the reasons behind each score
  • Suspicious Users table with filtering, sorting, search, and pagination
  • Manual statuses: active, safe, suspicious, and ignored
  • Manual login blocking and unblocking
  • Single-user and bulk deletion with permission and safety checks
  • Administrator protection enabled by default
  • Activity logs with configurable retention
  • Automatic daily cleanup of expired logs
  • Configurable risk thresholds
  • Scan progress, cancellation, and duplicate-scan protection
  • Optional removal of plugin data during uninstall

Safety First

The plugin does not automatically delete or block users.

Authorized administrators must review accounts manually before taking action. A risk score is only an indicator and may include false positives.

Administrator protection is enabled by default. Disabling this protection should be done only after carefully reviewing the possible consequences.

User deletion is permanent. Create a database backup before deleting user accounts from a production site, especially before using bulk deletion.

Privacy

Riskora User Scanner processes WordPress user account information locally to calculate risk scores and help authorized administrators review suspicious accounts.

The plugin does not transmit user account data, risk scores, scan results, or plugin logs to external services.

During analysis, the plugin may read user IDs, usernames, email addresses, roles, registration dates, profile data, and activity indicators already stored by WordPress.

The plugin may store:

  • User IDs, risk scores, risk levels, and score reasons
  • Manual review statuses
  • Login blocking status and related administrative metadata
  • Last login information collected after plugin activation
  • Scan dates, scan summaries, plugin settings, and activity logs

When a user is deleted through the plugin, the username and email address may remain in an activity log until that log entry reaches the configured retention period.

Logs are automatically removed according to the configured retention period.

Plugin data is retained during uninstall by default. Administrators can enable complete data removal in the plugin settings before uninstalling.

Suggested privacy policy text is available in the WordPress Privacy Policy Guide.