
Authyo Passwordless Login Security & Risk Analysis
wordpress.org/plugins/authyo-passwordless-loginEnable secure OTP login for WordPress with passwordless authentication using email-based one-time passwords (OTP) powered by Authyo.
Is Authyo Passwordless Login Safe to Use in 2026?
Generally Safe
Score 100/100Authyo Passwordless Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'authyo-passwordless-login' v1.0.3 plugin presents a mixed security posture. While it boasts no recorded vulnerabilities and a low number of external HTTP requests, the static analysis reveals several areas for concern. A significant portion of its attack surface, specifically 4 out of 9 AJAX handlers, lacks authentication checks. Additionally, both SQL queries within the plugin are not using prepared statements, which is a common vector for SQL injection vulnerabilities. The plugin also has a good output escaping rate at 84%, but this still leaves room for potential cross-site scripting (XSS) vulnerabilities in the remaining 16% of outputs. The absence of any taint analysis findings and a clean vulnerability history are positive indicators, suggesting that active exploitation of known issues is unlikely. However, the presence of unprotected entry points and raw SQL queries represent actionable risks that could be exploited by an attacker.
Key Concerns
- AJAX handlers without auth checks
- Raw SQL queries without prepared statements
Authyo Passwordless Login Security Vulnerabilities
Authyo Passwordless Login Code Analysis
SQL Query Safety
Output Escaping
Authyo Passwordless Login Attack Surface
AJAX Handlers 9
REST API Routes 1
Shortcodes 1
WordPress Hooks 19
Maintenance & Trust
Authyo Passwordless Login Maintenance & Trust
Maintenance Signals
Community Trust
Authyo Passwordless Login Alternatives
User Verification by PickPlugins
user-verification
Email verification for user registration to protect spam.
VentraConnect – Social Login, Magic Link & Email OTP (Passwordless)
ventraconnect-social-login
Social login with 15+ providers plus passwordless login (Magic Link & Email OTP), with Guardrails to block spam registrations.
Password Less Login
password-less-login
A powerful and easy-to-use WordPress plugin for passwordless and OTP-based login.
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Solid Security – Password, Two Factor Authentication, and Brute Force Protection
better-wp-security
Harden your site security with Login Security, Two-Factor Authentication (2FA), Vulnerability Scanner, Firewall, and more. Formerly iThemes Security.
Authyo Passwordless Login Developer Profile
10 plugins · 10 total installs
How We Detect Authyo Passwordless Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/authyo-passwordless-login/assets/css/login.css/wp-content/plugins/authyo-passwordless-login/assets/js/login.js/wp-content/plugins/authyo-passwordless-login/assets/js/login.jsauthyo-passwordless-login/assets/css/login.css?ver=authyo-passwordless-login/assets/js/login.js?ver=HTML / DOM Fingerprints
data-authyo-login-urldata-authyo-nonceauthyoPasswordlessLogin/wp-json/authyo-passwordless-login/v1/settings[authyo_login]