
Authenticator Security & Risk Analysis
wordpress.org/plugins/authenticatorThis plugin allows you to make your WordPress site accessible to logged in users only.
Is Authenticator Safe to Use in 2026?
Generally Safe
Score 99/100Authenticator has a strong security track record. Known vulnerabilities have been patched promptly.
The Authenticator plugin v1.3.1 exhibits a mixed security posture. While it has a small attack surface and implements a reasonable number of capability checks and a nonce check, there are significant concerns stemming from its code analysis and vulnerability history. The static analysis reveals that 100% of its SQL queries are not using prepared statements, which is a critical vulnerability vector for SQL injection. Furthermore, a concerning 71% of analyzed taint flows have unsanitized paths, indicating potential for insecure data handling and path traversal issues, although no critical or high severity taint flows were specifically identified in this scan. The vulnerability history highlights a past high-severity vulnerability related to missing authorization, which is a common and dangerous class of flaws. The fact that this high-severity vulnerability is now patched is positive, but the historical pattern of such issues warrants caution. Overall, the plugin has strengths in limiting its direct attack surface, but the lack of prepared statements for SQL and the past authorization issues suggest that careful review and potential remediation are necessary to improve its security.
Key Concerns
- 100% of SQL queries are not prepared
- 5 out of 7 taint flows have unsanitized paths
- Past high severity vulnerability (missing authorization)
- Only 20% of outputs are properly escaped
Authenticator Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Authenticator <= 1.3.0 - Missing Authorization
Authenticator Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Authenticator Attack Surface
AJAX Handlers 1
WordPress Hooks 16
Maintenance & Trust
Authenticator Maintenance & Trust
Maintenance Signals
Community Trust
Authenticator Alternatives
SN Extend Authentication
sn-extend-authentication
This plugin allows admin to disable anonymous (non authenticated users) browsing of selective posts, pages, feeds or complete WordPress site.
Private Website – Login Required
private-website
This plugin requires users to be logged in to view the website. Activate the plugin to enforce login, and deactivate it to remove the restriction.
MyASP MemberShip
myasp-membership
Membership plugin for MyASP Users.
Disable Dashboard Access
admin-only-dashboard
Disable Dashboard Access: Only admins can access the dashboard by default. Whitelist trusted users easily, quick setup, and secure.
LCK cloud Connector
lck-cloud-connector
Easily restrict access to your existing WordPress pages and posts. Official connector to build secure membership sites with LCK cloud.
Authenticator Developer Profile
3 plugins · 2K total installs
How We Detect Authenticator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/authenticator/css/admin.css/wp-content/plugins/authenticator/css/admin-layout.css/wp-content/plugins/authenticator/css/settings.css/wp-content/plugins/authenticator/js/admin.js/wp-content/plugins/authenticator/js/admin.jsauthenticator/css/admin.css?ver=authenticator/css/admin-layout.css?ver=authenticator/css/settings.css?ver=authenticator/js/admin.js?ver=HTML / DOM Fingerprints
authenticator-settings-wrapBEGIN: Authenticator PluginEND: Authenticator Plugindata-authenticator-nonceauthenticator_admin_params/wp-json/authenticator/v1/settings