
AH JWT Auth Security & Risk Analysis
wordpress.org/plugins/ah-jwt-authThis plugin allows sign in to WordPress using a JSON Web Token (JWT) contained in a HTTP Header.
Is AH JWT Auth Safe to Use in 2026?
Generally Safe
Score 92/100AH JWT Auth has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The ah-jwt-auth plugin v1.5.4 exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs and the plugin's track record of no recorded vulnerabilities further bolster this assessment. The code demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all outputs. There are no identified dangerous functions, file operations, or taint flows, which are significant indicators of a secure codebase. The attack surface is also minimal, with no unprotected entry points.
However, a few areas warrant attention. The presence of a single cron event, while not explicitly flagged as unprotected, represents a potential entry point that could be further scrutinized. The plugin also makes one external HTTP request, which, depending on its purpose and destination, could introduce external dependencies or risks if not handled with proper validation and security considerations. The lack of any nonce checks is a concern, especially if the cron event or external HTTP request could be triggered or manipulated by unauthenticated users. While capability checks are present, their effectiveness in securing all potential actions associated with the cron event or HTTP request cannot be definitively determined without further context.
Key Concerns
- External HTTP requests made
- Cron events present
- No nonce checks
AH JWT Auth Security Vulnerabilities
AH JWT Auth Release Timeline
AH JWT Auth Code Analysis
Output Escaping
AH JWT Auth Attack Surface
WordPress Hooks 6
Scheduled Events 1
Maintenance & Trust
AH JWT Auth Maintenance & Trust
Maintenance Signals
Community Trust
AH JWT Auth Alternatives
JWT Authenticator
jwt-authenticator
This plugin integrates JWT authentication and automates user creation.
Twelve Legs Marketing SSO
twelve-legs-marketing-sso
Single sign-on plugin for WordPress that accepts RS256 JWTs from the TWL SSO application for secure authentication.
Login for Google Apps
google-apps-login
Simple secure login and user management through your Google Workspace for WordPress (using oAuth2 and MFA if enabled).
Log in with Google
login-with-google
Minimal plugin that allows WordPress users to log in using Google.
Firebase Authentication
firebase-authentication
This plugin allows login into WordPress using Firebase user credentials and maps Firebase user data to WordPress user profile.
AH JWT Auth Developer Profile
1 plugin · 10 total installs
How We Detect AH JWT Auth
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ah-jwt-auth/assets/css/ahjwt-auth-admin.css/wp-content/plugins/ah-jwt-auth/assets/js/ahjwt-auth-admin.js/wp-content/plugins/ah-jwt-auth/assets/js/ahjwt-auth-frontend.js/wp-content/plugins/ah-jwt-auth/assets/js/ahjwt-auth-admin.js/wp-content/plugins/ah-jwt-auth/assets/js/ahjwt-auth-frontend.jsah-jwt-auth/assets/css/ahjwt-auth-admin.css?ver=ah-jwt-auth/assets/js/ahjwt-auth-admin.js?ver=ah-jwt-auth/assets/js/ahjwt-auth-frontend.js?ver=HTML / DOM Fingerprints
ahjwt-auth-admin-pageahjwt-auth-settings-fieldsdata-ahjwt-auth-actionahJwtAuthFrontend