
Check Login Lite Security & Risk Analysis
wordpress.org/plugins/check-login-liteA powerful security plugin to monitor login attempts, restrict access by IP or country, and receive alerts via email or Discord.
Is Check Login Lite Safe to Use in 2026?
Generally Safe
Score 100/100Check Login Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The check-login-lite v1.0.1 plugin exhibits a generally good security posture, with several strengths observed. The absence of dangerous functions, a lack of raw SQL queries (all using prepared statements), and a high percentage of properly escaped output are positive indicators. Furthermore, the presence of nonces and capability checks suggests an awareness of common WordPress security practices. The plugin also has a clean vulnerability history with no recorded CVEs, which is a strong sign of its stability and security over time.
However, there are specific areas that introduce risk. The most significant concern is the presence of a REST API route without a permission callback. This means that potentially sensitive data or functionality could be accessed or manipulated by unauthenticated users, creating a direct attack vector. While the total number of entry points is low and most are protected, this single unprotected endpoint is a notable weakness. The plugin also performs external HTTP requests, which, depending on the nature of these requests, could introduce risks if the external services are compromised or if the data sent is not properly sanitized.
In conclusion, check-login-lite v1.0.1 demonstrates good underlying security principles. Its clean vulnerability history and reliance on prepared statements are commendable. The primary weakness lies in an unprotected REST API endpoint, which requires immediate attention to mitigate the risk of unauthorized access or manipulation. The external HTTP requests should also be reviewed for potential vulnerabilities.
Key Concerns
- REST API route without permission callback
Check Login Lite Security Vulnerabilities
Check Login Lite Release Timeline
Check Login Lite Code Analysis
Output Escaping
Data Flow Analysis
Check Login Lite Attack Surface
REST API Routes 2
WordPress Hooks 7
Maintenance & Trust
Check Login Lite Maintenance & Trust
Maintenance Signals
Community Trust
Check Login Lite Alternatives
Hey Notify
hey-notify
Get notified when things happen in WordPress.
Update Notification
update-notification
WordPressの記事やページを更新した際に Discord、ChatWork、Slack、Telegram、Guilded、Google Chat に更新通知を送ることができます。
Activity Log – Monitor & Record User Changes
aryo-activity-log
This top rated Activity Log plugin helps you monitor & log all changes and actions on your WordPress site, so you can remain secure and organized.
Update Notifier
update-notifier
Sends email notifications if a new version of WordPress available. Notifications about updates for plugins and themes can also be sent.
Host Header Injection Fix
host-header-injection-fix
Sets custom headers for WP notification emails. Also fixes a security issue with WP versions < 5.5.
Check Login Lite Developer Profile
1 plugin · 0 total installs
How We Detect Check Login Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/check-login-lite/main.css/wp-content/plugins/check-login-lite/main.js/wp-content/plugins/check-login-lite/main.jscheck-login-lite/main.css?ver=check-login-lite/main.js?ver=HTML / DOM Fingerprints
checloli-login-formchecloli-admin-warning<!-- Main plugin logic --><!-- Basic Auth Form --><!-- END Basic Auth Form -->data-checloli-noncedata-checloli-actionchecloli_vars/wp-json/checloli/v1/auth