
BlaatLogin: OAuth Security & Risk Analysis
wordpress.org/plugins/blaatschaap-oauthThis plugin turns your WordPress website into an OAuth Consumer. It allowsallows your users to sign in with any OAuth provider.
Is BlaatLogin: OAuth Safe to Use in 2026?
Generally Safe
Score 100/100BlaatLogin: OAuth has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The blaatschaap-oauth plugin v0.4.5 presents a mixed security posture. On the positive side, there are no reported CVEs, indicating a history free of known public vulnerabilities. Furthermore, the plugin exhibits good practices regarding SQL query sanitation, with a high percentage utilizing prepared statements.
However, the static analysis reveals several areas of concern. A significant number of taint flows, specifically 7 out of 10 analyzed, involve unsanitized paths. This is further compounded by 2 high-severity taint flows, suggesting potential vulnerabilities where user-supplied data could be used in sensitive operations without proper sanitization. The plugin also has a moderate number of file operations and a significant portion of output not being properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user input is reflected directly. While the attack surface is reported as zero, this could be an artifact of the analysis tool and should be cautiously interpreted.
Overall, while the lack of historical CVEs is a positive sign, the static analysis results, particularly the taint flow analysis and output escaping, highlight potential weaknesses that require attention. The plugin's strengths lie in its SQL handling and absence of known vulnerabilities, but the identified taint flows and escaping issues represent a tangible risk.
Key Concerns
- High severity taint flows
- Unsanitized paths in taint flows
- Less than 100% properly escaped output
- File operations present
BlaatLogin: OAuth Security Vulnerabilities
BlaatLogin: OAuth Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
BlaatLogin: OAuth Attack Surface
WordPress Hooks 30
Maintenance & Trust
BlaatLogin: OAuth Maintenance & Trust
Maintenance Signals
Community Trust
BlaatLogin: OAuth Alternatives
Login for Google Apps
google-apps-login
Simple secure login and user management through your Google Workspace for WordPress (using oAuth2 and MFA if enabled).
Log in with Google
login-with-google
Minimal plugin that allows WordPress users to log in using Google.
Login with GitHub
login-with-github
Minimal plugin that allows WordPress users to log in using GitHub.
Secufor_OAuth
wpoauth
Secufor_OAuth is a WordPress plugin that enables Single Sign-On (SSO) functionality using the OAuth protocol.
JWT Authentication for WP REST API
jwt-authentication-for-wp-rest-api
Extends the WP REST API using JSON Web Tokens Authentication as an authentication method.
BlaatLogin: OAuth Developer Profile
2 plugins · 20 total installs
How We Detect BlaatLogin: OAuth
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/blaatschaap-oauth/css/bs-auth-btn.css/wp-content/plugins/blaatschaap-oauth/blaat_auth.cssHTML / DOM Fingerprints
bs-auth-btn