
Auto Logout Extended Security & Risk Analysis
wordpress.org/plugins/auto-logout-extendedAuto Logout Extended は自動ログアウトとログイン状態保存を拡張するプラグインです。
Is Auto Logout Extended Safe to Use in 2026?
Generally Safe
Score 100/100Auto Logout Extended has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of 'auto-logout-extended' v1.1.7 reveals a generally strong security posture with good coding practices observed. The absence of dangerous functions, 100% use of prepared statements for SQL queries, and complete output escaping are significant strengths. Furthermore, the presence of a nonce check, while lacking capability checks, indicates some awareness of security principles. The plugin also has a clean vulnerability history with zero recorded CVEs, suggesting a history of secure development or effective patching.
However, the complete lack of capability checks in the analyzed code is a notable concern. While there are no identified AJAX handlers or REST API routes without authentication, this could be an oversight. The absence of taint analysis flows, while positive in itself, might also be due to the limited attack surface analyzed or the specific nature of the plugin's functionality. The plugin's small attack surface of zero entry points is a significant positive, but the absence of capability checks on potential future entry points or existing ones that might have been missed by the analysis is a potential risk.
In conclusion, 'auto-logout-extended' v1.1.7 demonstrates good security hygiene in several key areas. The lack of identified vulnerabilities and the use of secure coding practices are commendable. The primary area for improvement lies in the implementation of robust capability checks to ensure that only authorized users can trigger specific actions, even if the current attack surface appears minimal and authenticated.
Key Concerns
- No capability checks found
Auto Logout Extended Security Vulnerabilities
Auto Logout Extended Code Analysis
Output Escaping
Auto Logout Extended Attack Surface
WordPress Hooks 14
Maintenance & Trust
Auto Logout Extended Maintenance & Trust
Maintenance Signals
Community Trust
Auto Logout Extended Alternatives
LoginWP (Formerly Peter's Login Redirect)
peters-login-redirect
Redirect users to different locations after they log in, log out and register based on different conditions.
User Menus – Nav Menu Visibility
user-menus
Show/hide menu items to logged in users, logged out users or specific user roles. Display logged in user details in menu. Add a logout link to menu.
Inactive Logout
inactive-logout
Automatically logout idle user sessions, with logout redirections and concurrent limit logins all in one place.
Login Logout Menu
login-logout-menu
Login Logout Menu is a handy plugin which allows you to add login, logout, register and profile menu items in your selected menu.
Login or Logout Menu Item
login-or-logout-menu-item
Add a dynamic "Login" or "Logout" menu item to any WordPress Menu and control redirects.
Auto Logout Extended Developer Profile
2 plugins · 60 total installs
How We Detect Auto Logout Extended
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/auto-logout-extended/css/al_ext.css/wp-content/plugins/auto-logout-extended/js/al_ext.js/wp-content/plugins/auto-logout-extended/js/al_ext.jsauto-logout-extended/css/al_ext.css?ver=auto-logout-extended/js/al_ext.js?ver=HTML / DOM Fingerprints
al_ext_config