Disable Lost Your Password Security & Risk Analysis

wordpress.org/plugins/disable-lost-your-password

License URI: http://www.gnu.org/licenses/gpl-2.0.html Disable Wordpress Login Screen "Lost Yoyr Password?" Option Usign Disable Lost Your P …

0 active installs v1.0.0 PHP + WP 4.4+ Updated Nov 25, 2018
disabledisable-lost-your-passwordpassword-resetwordpress-security
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Disable Lost Your Password Safe to Use in 2026?

Generally Safe

Score 85/100

Disable Lost Your Password has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "disable-lost-your-password" plugin v1.0.0 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries without prepared statements, unescaped output, file operations, external HTTP requests, or raw taint flows is commendable. Furthermore, the plugin's attack surface is completely protected, with no AJAX handlers, REST API routes, shortcodes, or cron events that are not subject to authentication checks. This indicates a deliberate effort to adhere to secure coding practices.

The plugin's vulnerability history is also clean, with no known CVEs recorded. This, combined with the clean static analysis, suggests a low risk of immediate exploitation. However, the complete lack of nonce and capability checks, while not directly flagged as a vulnerability in this analysis (due to the protected attack surface), represents a potential gap in defense-in-depth. While the current attack surface is secure, any future expansion or modification could introduce risks if these checks are not considered.

In conclusion, the plugin currently appears to be very secure. The developers have demonstrated good practice in avoiding common vulnerabilities. The only minor area for potential improvement lies in incorporating nonce and capability checks as a standard security measure, even for protected entry points, to further harden the plugin against unforeseen future threats or misconfigurations. The current risk is assessed as very low.

Key Concerns

  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

Disable Lost Your Password Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Disable Lost Your Password Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Disable Lost Your Password Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Disable Lost Your Password Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filtershow_password_fieldsdisable-lost-your-password.php:16
filterallow_password_resetdisable-lost-your-password.php:17
filtergettextdisable-lost-your-password.php:18
Maintenance & Trust

Disable Lost Your Password Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedNov 25, 2018
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Disable Lost Your Password Developer Profile

Great Guide Info

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Disable Lost Your Password

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Disable Lost Your Password