
Cloud SAML SSO – Single Sign On Login Security & Risk Analysis
wordpress.org/plugins/cloud-sso-single-sign-onWordPress SSO using SAML IDPs to enable single sign on using Azure AD, Office 365, Okta, ADFS, KeyCloak, OneLogin, Salesforce, Google Apps Gsuite
Is Cloud SAML SSO – Single Sign On Login Safe to Use in 2026?
Generally Safe
Score 94/100Cloud SAML SSO – Single Sign On Login has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of cloud-sso-single-sign-on v1.0.21 reveals a seemingly clean codebase in terms of immediate exploitable vulnerabilities. There are no detected AJAX handlers, REST API routes, shortcodes, cron events, dangerous functions, direct SQL queries, unescaped output, file operations, external HTTP requests, or instances of missing nonce/capability checks. The taint analysis also shows no identified unsanitized paths or critical/high severity flows. This suggests that the current version, from a static code perspective, has implemented good security practices for input handling and authorization within its accessible code paths. However, the plugin's vulnerability history is a significant concern. With 3 known CVEs, including 2 high and 1 medium severity, and common vulnerability types like Missing Authorization, Missing Authentication, and PHP Remote File Inclusion, it indicates a pattern of past security weaknesses. The fact that these issues were identified and patched in the past, with the last vulnerability dated 2025-09-05, suggests a history of potential security flaws that could be reintroduced or remain in older deployments. While the current static analysis is reassuring, the historical context warrants vigilance and suggests that the plugin may have had inherent architectural weaknesses that led to these past vulnerabilities.
Key Concerns
- Multiple past high/medium severity CVEs
- Bundled library Freemius v1.0 potentially outdated
- No nonce checks found
- No capability checks found
Cloud SAML SSO – Single Sign On Login Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Cloud SAML SSO <= 1.0.19 - Missing Authorization to Unauthenticated Settings Modification via set_organization_settings Action
Cloud SAML SSO <= 1.0.19 - Missing Authorization to Unauthenticated Identity Provider Deletion via delete_config Action
Cloud SAML SSO - Single Sign On Login <= 1.0.18 - Unauthenticated Local File Inclusion
Cloud SAML SSO – Single Sign On Login Code Analysis
Bundled Libraries
Cloud SAML SSO – Single Sign On Login Attack Surface
WordPress Hooks 3
Maintenance & Trust
Cloud SAML SSO – Single Sign On Login Maintenance & Trust
Maintenance Signals
Community Trust
Cloud SAML SSO – Single Sign On Login Alternatives
SAML Single Sign On – SSO Login
miniorange-saml-20-single-sign-on
SAML SSO (Single Sign On) for WordPress Login with Okta, Entra ID, Azure AD/B2C, G-Suite, Shibboleth, OneLogin, Keycloak, Salesforce [24/7 Support]
OneLogin SAML SSO
onelogin-saml-sso
This plugin provides single sign-on via SAML and gives users one-click access to their WordPress accounts from identity providers like OneLogin.
SSO Login – Universal (OAuth + SAML)
authress
SSO Login provides user login, business authentication, SSO, Social login, and Single Sign-On for all sites.
Frontegg SAML SSO
frontegg-saml-sso
Replace the WordPress login and logout flows with secure SAML-based authentication via Frontegg. Easily configure your SSO app from the admin panel.
OAuth Single Sign On – SSO (OAuth Client)
miniorange-login-with-eve-online-google-facebook
WordPress SSO (Single Sign On) with Azure, Azure B2C, Cognito, Okta, Classlink, Discord, Clever, Keycloak, OAuth & OpenID Providers [24/7 SUPPORT].
Cloud SAML SSO – Single Sign On Login Developer Profile
1 plugin · 100 total installs
How We Detect Cloud SAML SSO – Single Sign On Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cloud-sso-single-sign-on/assets/resources/images/logo.png