Auto Login After Registration Security & Risk Analysis

wordpress.org/plugins/auto-login-after-registration

This plugin allows users to easily add a simple user registration form and login form anywhere on their site using simple shortcode.

50 active installs v1.0.0 PHP + WP 3.5.0+ Updated Aug 20, 2016
loginregistrationregistration-formsignupuser-registartion
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEJul 8, 2025
Safety Verdict

Is Auto Login After Registration Safe to Use in 2026?

Use With Caution

Score 63/100

Auto Login After Registration has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Jul 8, 2025Updated 9yr ago
Risk Assessment

The 'auto-login-after-registration' plugin exhibits a mixed security posture. On the positive side, the static analysis shows no dangerous functions, all SQL queries use prepared statements, and there are no external HTTP requests or file operations, indicating good foundational security practices regarding common web vulnerabilities.

However, significant concerns arise from the analysis. Despite having few entry points, the presence of four unsanitized taint flows, all involving unescaped paths, is a critical red flag. This suggests that user-supplied input, if processed by these flows, could be manipulated to execute unintended code or access unauthorized resources. Furthermore, the complete lack of nonce and capability checks on entry points means that any user, regardless of their role or intent, could potentially trigger these insecure code paths. This, combined with a medium severity Cross-Site Scripting vulnerability in its history, paints a concerning picture.

The plugin's vulnerability history, specifically one medium-severity XSS vulnerability that remains unpatched, coupled with the identified taint flows, suggests a pattern of inadequate input sanitization and validation. While the current static analysis doesn't reveal a direct unpatched XSS, the historical data and the presence of unsanitized paths strongly indicate a persistent weakness in handling user-provided data. Therefore, while some aspects of the code are well-secured, the identified taint flow issues and historical vulnerabilities require immediate attention to mitigate potential risks.

Key Concerns

  • Unpatched CVE history (medium severity)
  • Taint flows with unsanitized paths (4 flows)
  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • Output escaping: 61% properly escaped (39% improperly)
Vulnerabilities
1

Auto Login After Registration Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-49946medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Auto Login After Registration <= 1.0.0 - Reflected Cross-Site Scripting

Jul 8, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Auto Login After Registration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

61% escaped18 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
alar_registration_shortcode (auto-login-after-registration.php:49)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Auto Login After Registration Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[registration-form] auto-login-after-registration.php:142
[login-form] auto-login-after-registration.php:185
WordPress Hooks 4
actionadmin_menuauto-login-after-registration.php:22
actionadmin_initauto-login-after-registration.php:35
actionwp_footerauto-login-after-registration.php:44
actionwp_login_failedauto-login-after-registration.php:190
Maintenance & Trust

Auto Login After Registration Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedAug 20, 2016
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs50
Developer Profile

Auto Login After Registration Developer Profile

Cynob IT Consultancy

9 plugins · 530 total installs

81
trust score
Avg Security Score
82/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Auto Login After Registration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/auto-login-after-registration/includes/admin-style.css/wp-content/plugins/auto-login-after-registration/includes/front-style.css/wp-content/plugins/auto-login-after-registration/includes/font-script.js
Script Paths
/wp-content/plugins/auto-login-after-registration/includes/font-script.js
Version Parameters
auto-login-after-registration/includes/front-style.css?ver=auto-login-after-registration/includes/font-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
alar-registration-formalar-registration-headingalar-login-formalar-login-headingftxtfbtn
Data Attributes
id="com_firstname"name="com_firstname"id="com_lastname"name="com_lastname"id="com_username"name="com_username"+14 more
JS Globals
ALAR_REGISTRATION_PAGE_DIRECTORYALAR_REGISTRATION_INCLUDE_URLalar_auto_login_plugin_menualar_logo_plugin_pagesalar_admin_cssalar_slider_trigger+3 more
Shortcode Output
[registration-form][login-form]
FAQ

Frequently Asked Questions about Auto Login After Registration