
DE Social Login Security & Risk Analysis
wordpress.org/plugins/de-social-loginA Simple wordpress plugin which enable the user to login in wordress site with Google/Facebook/Twitter/LinkedIn/Yahoo/OpenId accounts with one click.
Is DE Social Login Safe to Use in 2026?
Generally Safe
Score 85/100DE Social Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The de-social-login plugin v1.0.2 exhibits a mixed security posture. On the positive side, it has a very small attack surface with only one shortcode and no AJAX handlers or REST API routes exposed without authentication. The plugin also shows good practices by utilizing prepared statements for a significant majority of its SQL queries and having no known CVEs. However, there are significant areas of concern that detract from its overall security.
The most critical issues stem from the code analysis. The presence of the 'unserialize' function is a major red flag, as unserialization of untrusted data can lead to remote code execution vulnerabilities. Coupled with this, the plugin lacks any nonce checks or capability checks, meaning that even though the entry points are limited, they are not adequately protected against unauthorized access or manipulation. Furthermore, the static analysis indicates that 100% of the output is not properly escaped, which is a serious deficiency that can lead to cross-site scripting (XSS) vulnerabilities.
The absence of any past vulnerability history is a positive indicator, suggesting the plugin may not have been a target or has been developed with a degree of care. However, the existing code signals of dangerous functions and unsanitized taint flows, along with the complete lack of output escaping and authorization checks, present immediate and exploitable risks that outweigh the lack of historical issues. The plugin's strengths lie in its limited attack surface and SQL practices, but these are overshadowed by critical vulnerabilities in data handling, authorization, and output sanitization.
Key Concerns
- Presence of 'unserialize' function
- 100% of output not properly escaped
- 0 Nonce checks
- 0 Capability checks
- Flows with unsanitized paths
DE Social Login Security Vulnerabilities
DE Social Login Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
DE Social Login Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
DE Social Login Maintenance & Trust
Maintenance Signals
Community Trust
DE Social Login Alternatives
Wp Social Login and Register Social Counter
wp-social
Wp social lets you add social login, social counter, and social share buttons of different styles to your WordPress website.
WP Social AutoConnect
wp-fb-autoconnect
A lightweight but powerful Facebook login plugin, easy to setup and transparent to new and returning users alike. Supports Buddypress.
LoginPress | wp-login Custom Login Page Customizer
loginpress
LoginPress is a Custom Login Page Customizer plugin allows you to easily customize the layout of login, admin login, client login, register pages.
Nextend Social Login and Register
nextend-facebook-connect
One click registration & login plugin for Facebook, Google, X (formerly Twitter) and more. Quick setup and easy configuration.
Custom Login Page Customizer – Login Designer
login-designer
Login Designer is the best way to style a custom login page for your WordPress login, register and forgot password forms, right from the live-action W …
DE Social Login Developer Profile
1 plugin · 10 total installs
How We Detect DE Social Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/de-social-login/js/sociallogin.js/wp-content/plugins/de-social-login/css/sociallogin.css/wp-content/plugins/de-social-login/js/script.js/wp-content/plugins/de-social-login/css/style.css/wp-content/plugins/de-social-login/js/admin.js/wp-content/plugins/de-social-login/js/loginBySocialID.js/wp-content/plugins/de-social-login/js/login.js/wp-content/plugins/de-social-login/js/sociallogin.js/wp-content/plugins/de-social-login/js/script.js/wp-content/plugins/de-social-login/js/admin.js/wp-content/plugins/de-social-login/js/loginBySocialID.js/wp-content/plugins/de-social-login/js/login.jsde-social-login/sociallogin.js?ver=de-social-login/sociallogin.css?ver=de-social-login/script.js?ver=de-social-login/style.css?ver=de-social-login/admin.js?ver=de-social-login/loginBySocialID.js?ver=de-social-login/login.js?ver=HTML / DOM Fingerprints
de-help-buttonde-newsdesl-social-login-content<!-- WP Social Login Settings --><!-- Facebook Settings --><!-- Twitter Settings --><!-- Google Settings -->+4 moredata-providerdata-uidloginByOpenID_PATHdeSocialLoginSettingsdesl_install_plugindesl_login_errorsde_social_login_settings_pagede_social_login_facebook_settings_page+6 more[de_social_login]