
OpenID Connect Generic Client Security & Risk Analysis
wordpress.org/plugins/daggerhart-openid-connect-genericA simple client that provides SSO or opt-in authentication against a generic OAuth2 Server implementation.
Is OpenID Connect Generic Client Safe to Use in 2026?
Generally Safe
Score 98/100OpenID Connect Generic Client has a strong security track record. Known vulnerabilities have been patched promptly.
The "daggerhart-openid-connect-generic" plugin, version 3.11.3, presents a mixed security posture. While it demonstrates strong practices in output escaping, with 100% of outputs properly handled, and no critical or high-severity vulnerabilities historically, there are notable areas of concern. The presence of two AJAX handlers without authentication checks creates a significant attack surface. Additionally, all four analyzed taint flows showed unsanitized paths, though thankfully none reached critical or high severity. This indicates a potential for issues if input validation is not meticulously handled within these flows. The plugin has a history of two medium-severity vulnerabilities, both related to Cross-site Scripting (XSS), suggesting a recurring pattern of input sanitization weaknesses that need careful attention. The last reported vulnerability being in the future (2025) is unusual and should be verified as a potential data anomaly. Overall, the plugin has good output handling but requires immediate attention to its unauthenticated entry points and the ongoing pattern of unsanitized input flows to mitigate potential security risks.
Key Concerns
- Unprotected AJAX handlers
- Taint flows with unsanitized paths
- Medium severity vulnerabilities (XSS)
OpenID Connect Generic Client Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
OpenID Connect Generic Client <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
OpenID Connect Generic Client 3.8.0-3.8.1 - Reflected Cross-Site Scripting
OpenID Connect Generic Client Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
OpenID Connect Generic Client Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 16
Scheduled Events 1
Maintenance & Trust
OpenID Connect Generic Client Maintenance & Trust
Maintenance Signals
Community Trust
OpenID Connect Generic Client Alternatives
Hellō Login
hello-login
Free and simple to setup plugin provides registration and login with the Hellō Wallet. Users choose from popular social login, email, or phone.
Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall
limit-login-attempts-reloaded
Block excessive login attempts and protect your site against brute force attacks. Simple, yet powerful tools to improve site performance.
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Loginizer
loginizer
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Security Optimizer – The All-In-One Protection Plugin
sg-security
Secure your WordPress site from brute-force attacks, threats, malware, and bots. Free to use and easy to set up.
OpenID Connect Generic Client Developer Profile
4 plugins · 11K total installs
How We Detect OpenID Connect Generic Client
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/daggerhart-openid-connect-generic/assets/css/style.css/wp-content/plugins/daggerhart-openid-connect-generic/assets/js/login-form.js/wp-content/plugins/daggerhart-openid-connect-generic/assets/js/openid-connect-generic.js/wp-content/plugins/daggerhart-openid-connect-generic/assets/css/style.css?ver=/wp-content/plugins/daggerhart-openid-connect-generic/assets/js/login-form.js?ver=/wp-content/plugins/daggerhart-openid-connect-generic/assets/js/openid-connect-generic.js?ver=HTML / DOM Fingerprints
daggerhart-openid-connect-generic-login-form<!-- OpenID Connect Generic Plugin --><!-- OpenID Connect Generic Login Form -->data-login-urldata-logout-urlOpenID_Connect_Generic_Login_Form_JSopenid_connect_generic_params/wp-json/oidc-generic/v1/settings[openid_connect_generic_auth_url]