
Bifröst – Instant Passwordless Temporary Login Links Security & Risk Analysis
wordpress.org/plugins/create-temporary-login🔗️ Create passwordless temporary login links. Instantly ⚡️
Is Bifröst – Instant Passwordless Temporary Login Links Safe to Use in 2026?
Generally Safe
Score 97/100Bifröst – Instant Passwordless Temporary Login Links has a strong security track record. Known vulnerabilities have been patched promptly.
The 'create-temporary-login' plugin version 1.0.9 exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, file operations, external HTTP requests, and the use of prepared statements for SQL queries are positive indicators. Furthermore, the presence of nonce and capability checks, along with a high percentage of properly escaped output, suggest diligent security practices in its code. The limited attack surface, with all entry points protected, is also a significant strength.
However, the plugin's vulnerability history raises a notable concern. It has had one known CVE, specifically of high severity, related to missing authorization. While this vulnerability is currently patched, its existence and type indicate a historical weakness that warrants attention. The taint analysis showing zero flows with unsanitized paths is reassuring, but the past high-severity authorization issue implies that thorough auditing of authorization logic, especially for AJAX handlers, remains crucial.
In conclusion, while the current version of 'create-temporary-login' demonstrates strong adherence to many security best practices, the past high-severity vulnerability related to authorization is a weakness. Users should remain vigilant and ensure they are always running the latest patched version of the plugin. The plugin's overall security is good, but the historical authorization flaw is a point of caution.
Key Concerns
- High severity vulnerability in history
- Missing authorization vulnerability type historically
Bifröst – Instant Passwordless Temporary Login Links Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WPBifröst – Instant Passwordless Temporary Login Links <= 1.0.7 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
Bifröst – Instant Passwordless Temporary Login Links Code Analysis
Output Escaping
Bifröst – Instant Passwordless Temporary Login Links Attack Surface
AJAX Handlers 1
WordPress Hooks 8
Maintenance & Trust
Bifröst – Instant Passwordless Temporary Login Links Maintenance & Trust
Maintenance Signals
Community Trust
Bifröst – Instant Passwordless Temporary Login Links Alternatives
Temporary Login
temporary-login
Create a secure, temporary URL for easy access to your WP admin.
Temporary Login Without Password
temporary-login-without-password
Create self-expiring, temporary admin accounts. Easily share direct login links (no need for username/password) with your developers or editors.
Password Protect – Temporary Login Without Password & Password Protect Entire Site
smart-password-protect
Password Protect entire site & create Temporary Login Without Password links. Simple & secure access for developers or maintenance.
Login Links – Passwordless Login, Temporary Access Links & Custom Login Form
login-links
Create secure self-expiring login links for temporary access and guest users, and enable passwordless login for registered ones.
SafeTemp Login – Temporary Access with Approval
safetemplogin-tawa
Create temporary users with any role. When a temporary user is an administrator, sensitive actions require approval from a real administrator.
Bifröst – Instant Passwordless Temporary Login Links Developer Profile
4 plugins · 760 total installs
How We Detect Bifröst – Instant Passwordless Temporary Login Links
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/create-temporary-login/admin/css/admin.css/wp-content/plugins/create-temporary-login/admin/js/admin.js/wp-content/plugins/create-temporary-login/admin/js/admin.jscreate-temporary-login/admin/css/admin.css?ver=create-temporary-login/admin/js/admin.js?ver=HTML / DOM Fingerprints
ctl_generate_linkctl_tokensctl_tokenctl_token_urlctl_token_userctl_token_rolectl_token_expiresctl_token_actionsIf current user is a temporary user and
*
* want to access the `Plugin Settings` page using the linkRedirect the user to the `Dashboard > index.php`data-urldata-instructionctl_admin_ajax_object