
Authyo Passwordless Login Security & Risk Analysis
wordpress.org/plugins/authyo-passwordless-loginWordPress login security with brute-force protection, IP manager, security logs, XML-RPC protection, REST API protection, and passwordless OTP login.
Is Authyo Passwordless Login Safe to Use in 2026?
Generally Safe
Score 100/100Authyo Passwordless Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'authyo-passwordless-login' v1.0.3 plugin presents a mixed security posture. While it boasts no recorded vulnerabilities and a low number of external HTTP requests, the static analysis reveals several areas for concern. A significant portion of its attack surface, specifically 4 out of 9 AJAX handlers, lacks authentication checks. Additionally, both SQL queries within the plugin are not using prepared statements, which is a common vector for SQL injection vulnerabilities. The plugin also has a good output escaping rate at 84%, but this still leaves room for potential cross-site scripting (XSS) vulnerabilities in the remaining 16% of outputs. The absence of any taint analysis findings and a clean vulnerability history are positive indicators, suggesting that active exploitation of known issues is unlikely. However, the presence of unprotected entry points and raw SQL queries represent actionable risks that could be exploited by an attacker.
Key Concerns
- AJAX handlers without auth checks
- Raw SQL queries without prepared statements
Authyo Passwordless Login Security Vulnerabilities
Authyo Passwordless Login Release Timeline
Authyo Passwordless Login Code Analysis
SQL Query Safety
Output Escaping
Authyo Passwordless Login Attack Surface
AJAX Handlers 9
REST API Routes 1
Shortcodes 1
WordPress Hooks 19
Maintenance & Trust
Authyo Passwordless Login Maintenance & Trust
Maintenance Signals
Community Trust
Authyo Passwordless Login Alternatives
DoLogin Security
dologin
Easy Login. 2FA login. Passwordless login. reCAPTCHA. GeoLocation (Continent/Country/City)/IP range to limit login attempts. Whitelist and Blacklist.
Kaya Login Captcha
kaya-login-captcha
Adds a simple captcha on login form, register form and lost-password form.
Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection
admin-safety-guard
Protect your WP site from hackers for free. Limit logins, add 2FA, reCAPTCHA, block IPs, hide wp-login.php & track activity logs.
Fortress Login Pro – Secure, Hide & Rename Login URL
fortress-login-pro
Hide and rotate your WordPress login URL. Track access, export logs, and prevent brute-force attacks with real-time visibility.
Simple Login Guard – Monitor & Block Attempts
simple-login-guard
Monitor failed login attempts and automatically block IPs after multiple failures. Lightweight and easy to use.
Authyo Passwordless Login Developer Profile
16 plugins · 40 total installs
How We Detect Authyo Passwordless Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/authyo-passwordless-login/assets/css/login.css/wp-content/plugins/authyo-passwordless-login/assets/js/login.js/wp-content/plugins/authyo-passwordless-login/assets/js/login.jsauthyo-passwordless-login/assets/css/login.css?ver=authyo-passwordless-login/assets/js/login.js?ver=HTML / DOM Fingerprints
data-authyo-login-urldata-authyo-nonceauthyoPasswordlessLogin/wp-json/authyo-passwordless-login/v1/settings[authyo_login]