
Cyberus Key Security & Risk Analysis
wordpress.org/plugins/cyberus-keyCyberus Key eliminates passwords using one-time tokens delivered via ultrasounds.
Is Cyberus Key Safe to Use in 2026?
Mostly Safe
Score 84/100Cyberus Key is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved.
The "cyberus-key" plugin v1.1 presents a mixed security posture. While it demonstrates good practices in its use of prepared statements for SQL queries and a high percentage of properly escaped output, significant concerns arise from its attack surface and lack of robust security checks. The presence of one unprotected REST API route is a critical vulnerability, providing an easily exploitable entry point for attackers. Furthermore, the complete absence of nonce and capability checks across all entry points is alarming, suggesting a broad susceptibility to various attack vectors such as Cross-Site Request Forgery (CSRF) and unauthorized privilege escalation. The plugin's history of two medium-severity Cross-Site Scripting (XSS) vulnerabilities, with the last one occurring in March 2023, indicates a recurring pattern of input sanitization issues. Although there are no currently unpatched CVEs, this history, coupled with the identified code weaknesses, points to a plugin that requires immediate attention to secure its exposed functionalities.
Key Concerns
- Unprotected REST API route
- No nonce checks on entry points
- No capability checks on entry points
- History of XSS vulnerabilities
Cyberus Key Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Cyberus Key <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'uid' in 'cyberkey_settings' Plugin Setting
Cyberus Key <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Cyberus Key Release Timeline
Cyberus Key Code Analysis
Output Escaping
Cyberus Key Attack Surface
REST API Routes 1
WordPress Hooks 5
Maintenance & Trust
Cyberus Key Maintenance & Trust
Maintenance Signals
Community Trust
Cyberus Key Alternatives
ElIoT Pro Passwordless Login
eliot-pro
ElIoT Pro eliminates passwords using one-time tokens delivered via ultrasounds.
Keyless Auth – Login without Passwords
keyless-auth
Secure, passwordless authentication for WordPress. Your users login via magic email links – no passwords to remember or forget.
Passwordless Entry
passwordless-entry
WordPress Passwordless Entry is a plugin which allows users to authenticate into a WordPress installation against an existing account, without knowled …
Dolutech Passwordless Login
dolutech-passwordless-login
Permite login seguro sem senha com tecnologia passwordless e autenticação de dois fatores (2FA) via TOTP.
Two Factor
two-factor
Enable Two-Factor Authentication (2FA) using time-based one-time passwords (TOTP), email, and backup verification codes.
Cyberus Key Developer Profile
2 plugins · 0 total installs
How We Detect Cyberus Key
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cyberus-key/js/cyberuskey.min.js/wp-content/plugins/cyberus-key/js/integration.js/wp-content/plugins/cyberus-key/css/style.css/wp-content/plugins/cyberus-key/js/cyberuskey.min.js/wp-content/plugins/cyberus-key/js/integration.jsHTML / DOM Fingerprints
cyberkey_ajax_object/wp-json/api/login/