
Check Last Login Security & Risk Analysis
wordpress.org/plugins/check-last-loginSimple plugin which checks user's login status and displays registration date and last login date columns on the "Users" page.
Is Check Last Login Safe to Use in 2026?
Generally Safe
Score 85/100Check Last Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "check-last-login" plugin version 0.6 exhibits a generally positive security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or direct file operations significantly limits the potential attack surface. Furthermore, the absence of dangerous functions, external HTTP requests, and taint flows with unsanitized paths are strong indicators of secure coding practices in these areas. The plugin also has no recorded vulnerability history, which is a positive sign of its long-term stability and security.
However, there are critical concerns regarding its handling of data. The presence of SQL queries that are not using prepared statements is a significant risk, potentially leading to SQL injection vulnerabilities. Additionally, the lack of proper output escaping for all identified outputs means that any data displayed to users could be vulnerable to cross-site scripting (XSS) attacks. The complete absence of nonce checks and capability checks also suggests a lack of robust authorization and protection against common WordPress attack vectors. While the plugin has no known CVEs, the identified code-level vulnerabilities present a clear and present danger that requires immediate attention. It is crucial to address the SQL injection and XSS risks to improve the plugin's overall security.
Key Concerns
- SQL queries not using prepared statements
- Output escaping not properly implemented
- Missing nonce checks
- Missing capability checks
Check Last Login Security Vulnerabilities
Check Last Login Release Timeline
Check Last Login Code Analysis
SQL Query Safety
Output Escaping
Check Last Login Attack Surface
WordPress Hooks 7
Scheduled Events 1
Maintenance & Trust
Check Last Login Maintenance & Trust
Maintenance Signals
Community Trust
Check Last Login Alternatives
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
userswp
Light weight Front-end login form, User Registration, User Profile and Members Directory plugin.
JSON API User
json-api-user
Extends the JSON API Plugin to allow RESTful user registration, authentication & many other User Meta, BP functions. A Pro version is also available.
Pie Register – User Registration, Profiles & Content Restriction
pie-register
Create customized registration forms, Invite through email, Email Notification, User Roles assignment, and more. Pie Register is a User Registration p …
User Registration Using Contact Form 7
user-registration-using-contact-form-7
User Registration Using Contact Form 7 plugin provides the feature to register the user to the website.
MyASP MemberShip
myasp-membership
Membership plugin for MyASP Users.
Check Last Login Developer Profile
8 plugins · 140 total installs
How We Detect Check Last Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapform-tablename="allow_deletion"value="1"checked="checked"name="inactive_days"size="1"value="30"<div class="wrap"><h1>Check Last Login Settings</h1>