
Authyo OTP for Ninja Forms Security & Risk Analysis
wordpress.org/plugins/authyo-otp-for-ninja-formsIntegrate Authyo OTP verification seamlessly with Ninja Forms.
Is Authyo OTP for Ninja Forms Safe to Use in 2026?
Generally Safe
Score 100/100Authyo OTP for Ninja Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'authyo-otp-for-ninja-forms' plugin, version 1.0.4, exhibits a generally good security posture, particularly in its handling of SQL queries, which are 100% prepared, and a high rate of output escaping (87%). The plugin also demonstrates good practice by including nonce checks for its entry points and employing capability checks where appropriate. The absence of recorded vulnerabilities in its history is a positive indicator of past security diligence. However, a significant concern arises from the presence of 7 AJAX handlers, of which 4 lack any authentication checks. This creates a considerable attack surface, potentially exposing the plugin to unauthorized actions if these handlers are not adequately protected by other means. While no critical or high severity taint flows were detected, the unprotected AJAX endpoints remain the most prominent risk.
Key Concerns
- AJAX handlers without auth checks
- Limited output escaping on some outputs
Authyo OTP for Ninja Forms Security Vulnerabilities
Authyo OTP for Ninja Forms Code Analysis
Output Escaping
Data Flow Analysis
Authyo OTP for Ninja Forms Attack Surface
AJAX Handlers 7
REST API Routes 2
WordPress Hooks 18
Maintenance & Trust
Authyo OTP for Ninja Forms Maintenance & Trust
Maintenance Signals
Community Trust
Authyo OTP for Ninja Forms Alternatives
User Verification by PickPlugins
user-verification
Email verification for user registration to protect spam.
Email OTP Login with default login form
email-otp-login-with-default-login-form
Adds email OTP (One-Time Password) verification after valid login credentials on the default wp-login.php form for added security.
Email OTP Login
email-otp-login
Adds OTP (One-Time Password) verification after login for enhanced security in WordPress. OTP is sent to the user's email.
Authyo OTP for Contact Form 7
authyo-otp-for-contact-form-7
Adds OTP verification (Email, SMS, WhatsApp, Voice Call) and Google Sheets Integration (with Multi-Sheet support) to Contact Form 7.
Naimur Email OTP Verification for WooCommerce
naimur-email-otp-for-woocommerce
Short Description: Verify WooCommerce customer email addresses with a 6-digit OTP before account creation for secure and spam-free registrations.
Authyo OTP for Ninja Forms Developer Profile
10 plugins · 10 total installs
How We Detect Authyo OTP for Ninja Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/authyo-otp-for-ninja-forms/admin/css/authyo-admin.css/wp-content/plugins/authyo-otp-for-ninja-forms/admin/js/authyo-admin.js/wp-content/plugins/authyo-otp-for-ninja-forms/includes/js/authyo-public.jsjs/authyo-admin.jsauthyo-public.jsauthyo-otp-for-ninja-forms/admin/css/authyo-admin.css?ver=authyo-otp-for-ninja-forms/admin/js/authyo-admin.js?ver=authyo-otp-for-ninja-forms/includes/js/authyo-public.js?ver=HTML / DOM Fingerprints
authyo-otp-settingsdata-noncedata-ajax-urldata-securitydata-authyo-otp-form-idauthyo_otp_ajax_object