
AWEOS Admin Login Security & Risk Analysis
wordpress.org/plugins/aweos-admin-loginLogin without a password: Use this plugin to login via email verification, no password required.
Is AWEOS Admin Login Safe to Use in 2026?
Generally Safe
Score 85/100AWEOS Admin Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "aweos-admin-login" plugin, version 1.5.13, presents a significant security risk primarily due to its unprotected entry points. The static analysis reveals four AJAX handlers that lack any authentication or capability checks. This means any user, even unauthenticated ones, could potentially interact with these handlers, leading to unintended actions or information disclosure if the underlying code is vulnerable. While the plugin demonstrates good practices in SQL query handling and has no recorded vulnerability history, the absence of basic security measures on its AJAX endpoints is a critical oversight. The taint analysis indicates potential issues with unsanitized paths, which, combined with the unprotected AJAX handlers, could be exploited for path traversal or arbitrary file read/write vulnerabilities. The lack of nonce checks on these handlers further exacerbates this risk.
Key Concerns
- Unprotected AJAX handlers
- Taint analysis shows unsanitized paths
- Missing nonce checks
- Some outputs not properly escaped
AWEOS Admin Login Security Vulnerabilities
AWEOS Admin Login Code Analysis
Output Escaping
Data Flow Analysis
AWEOS Admin Login Attack Surface
AJAX Handlers 4
WordPress Hooks 6
Maintenance & Trust
AWEOS Admin Login Maintenance & Trust
Maintenance Signals
Community Trust
AWEOS Admin Login Alternatives
Magic Link – Secure one click passwordless login
magic-link
Secure one click passwordless login
User Verification by PickPlugins
user-verification
Email verification for user registration to protect spam.
Email OTP Authenticator – for Login, Registration or 2FA, RWL, RWA Services
email-otp-authenticator
Use an OTP to Login, Register, 2FA OR allow interim premium access WITHOUT Login, even WITHOUT Account. It is FAST, FRIENDLY, SMART, SMOOTH & SECURED.
Magic Login Mail or QR Code
magic-login-mail
Enter your email address, and send you an email with a magic link or QR Code to login without a password.
Smart WP Login
smart-wp-login
remove username, login, registration, password, authentication, wp-login, email, smart Requires at least: 3.1.0 Tested up to: 4.2.2 Stable tag: 1.0.
AWEOS Admin Login Developer Profile
10 plugins · 6K total installs
How We Detect AWEOS Admin Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/aweos-admin-login/public/style.css/wp-content/plugins/aweos-admin-login/public/verification.js/wp-content/plugins/aweos-admin-login/public/verification.jsaweos-admin-login/public/style.css?ver=aweos-admin-login/public/verification.js?ver=HTML / DOM Fingerprints
awal_verificationawal_midid="sender"id="verificator"id="info"