Bifröst – Instant Passwordless Temporary Login Links Security & Risk Analysis

wordpress.org/plugins/create-temporary-login

🔗️ Create passwordless temporary login links. Instantly ⚡️

50 active installs v1.0.9 PHP 7.4+ WP 6.2+ Updated Mar 5, 2026
loginpasswordless-logintemporary-accesstemporary-login
97
A · Safe
CVEs total1
Unpatched0
Last CVEOct 14, 2025
Safety Verdict

Is Bifröst – Instant Passwordless Temporary Login Links Safe to Use in 2026?

Generally Safe

Score 97/100

Bifröst – Instant Passwordless Temporary Login Links has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 14, 2025Updated 29d ago
Risk Assessment

The 'create-temporary-login' plugin version 1.0.9 exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, file operations, external HTTP requests, and the use of prepared statements for SQL queries are positive indicators. Furthermore, the presence of nonce and capability checks, along with a high percentage of properly escaped output, suggest diligent security practices in its code. The limited attack surface, with all entry points protected, is also a significant strength.

However, the plugin's vulnerability history raises a notable concern. It has had one known CVE, specifically of high severity, related to missing authorization. While this vulnerability is currently patched, its existence and type indicate a historical weakness that warrants attention. The taint analysis showing zero flows with unsanitized paths is reassuring, but the past high-severity authorization issue implies that thorough auditing of authorization logic, especially for AJAX handlers, remains crucial.

In conclusion, while the current version of 'create-temporary-login' demonstrates strong adherence to many security best practices, the past high-severity vulnerability related to authorization is a weakness. Users should remain vigilant and ensure they are always running the latest patched version of the plugin. The plugin's overall security is good, but the historical authorization flaw is a point of caution.

Key Concerns

  • High severity vulnerability in history
  • Missing authorization vulnerability type historically
Vulnerabilities
1

Bifröst – Instant Passwordless Temporary Login Links Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2025-10299high · 8.8Missing Authorization

WPBifröst – Instant Passwordless Temporary Login Links <= 1.0.7 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation

Oct 14, 2025 Patched in 1.0.8 (3d)
Code Analysis
Analyzed Mar 16, 2026

Bifröst – Instant Passwordless Temporary Login Links Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
24 escaped
Nonce Checks
4
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped25 total outputs
Attack Surface

Bifröst – Instant Passwordless Temporary Login Links Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_ctl_create_linkincludes\class-admin.php:61
WordPress Hooks 8
actionplugins_loadedcreate-temporary-login.php:50
actionadmin_menuincludes\class-admin.php:57
actionadmin_enqueue_scriptsincludes\class-admin.php:59
actiontemplate_redirectincludes\class-admin.php:63
filterallow_password_resetincludes\class-admin.php:67
filterwp_authenticate_userincludes\class-admin.php:69
actionadmin_initincludes\class-admin.php:71
actionwp_dashboard_setupincludes\class-option.php:47
Maintenance & Trust

Bifröst – Instant Passwordless Temporary Login Links Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 5, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Bifröst – Instant Passwordless Temporary Login Links Developer Profile

Hakik Zaman

4 plugins · 760 total installs

97
trust score
Avg Security Score
95/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect Bifröst – Instant Passwordless Temporary Login Links

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/create-temporary-login/admin/css/admin.css/wp-content/plugins/create-temporary-login/admin/js/admin.js
Script Paths
/wp-content/plugins/create-temporary-login/admin/js/admin.js
Version Parameters
create-temporary-login/admin/css/admin.css?ver=create-temporary-login/admin/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
ctl_generate_linkctl_tokensctl_tokenctl_token_urlctl_token_userctl_token_rolectl_token_expiresctl_token_actions
HTML Comments
If current user is a temporary user and * * want to access the `Plugin Settings` page using the linkRedirect the user to the `Dashboard > index.php`
Data Attributes
data-urldata-instruction
JS Globals
ctl_admin_ajax_object
FAQ

Frequently Asked Questions about Bifröst – Instant Passwordless Temporary Login Links