
DoLogin Security Security & Risk Analysis
wordpress.org/plugins/dologinEasy Login. 2FA login. Passwordless login. reCAPTCHA. GeoLocation (Continent/Country/City)/IP range to limit login attempts. Whitelist and Blacklist.
Is DoLogin Security Safe to Use in 2026?
Use With Caution
Score 64/100DoLogin Security has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "dologin" v4.3 plugin presents a mixed security posture. While it shows strengths in its SQL query handling, with a high percentage of prepared statements, and a lack of bundled libraries, several concerning areas emerge from the static analysis and historical vulnerability data. The significant number of flows with unsanitized paths, particularly those flagged as high severity in the taint analysis, alongside a considerable portion of output not being properly escaped, indicates a high risk of cross-site scripting (XSS) and other injection vulnerabilities. Furthermore, the presence of REST API routes without permission callbacks creates direct attack vectors that could be leveraged by unauthenticated users. The plugin's history of four known CVEs, including a high-severity one, across common vulnerability types like Missing Authorization and XSS, suggests a recurring pattern of insecure coding practices. Despite the absence of currently unpatched CVEs, the ongoing risk associated with these historical issues and the identified static analysis concerns warrants caution. The combination of unprotected entry points and a history of security flaws necessitates careful consideration before deployment.
Key Concerns
- High severity taint flows
- Unsanitized paths
- Low percentage of properly escaped output
- REST API routes without permission callbacks
- Presence of high severity past CVE
- History of medium severity past CVEs
DoLogin Security Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
DoLogin Security <= 4.3 - Unauthenticated Authentication Bypass via Insufficient Randomness via 'dologin' Parameter Weak PRNG Token
DoLogin Security <= 3.7.1 - Missing Authorization via REST Endpoints
DoLogin Security <= 3.7 - Missing Authorization on Dashboard Widget
DoLogin Security <= 3.6 - Unauthenticated Stored Cross-Site Scripting
DoLogin Security <= 3.6 - IP Address Spoofing
DoLogin Security Release Timeline
DoLogin Security Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
DoLogin Security Attack Surface
REST API Routes 4
WordPress Hooks 32
Maintenance & Trust
DoLogin Security Maintenance & Trust
Maintenance Signals
Community Trust
DoLogin Security Alternatives
Melapress Login Security
melapress-login-security
Enforce WordPress login and password security policies to protect user accounts and prevent unauthorized logins.
Cartpauj Register Captcha
cartpauj-register-captcha
Cartpauj Register Captcha does one simple task. It prevents SPAM signups through WordPress' default registration form.
Power Captcha reCAPTCHA
power-captcha-recaptcha
Protect WordPress/WooCommerce/Contact Form 7 forms from spam, brute-force attacks, fake comments, accounts, or registrations with Google reCAPTCHA.
Jeba Limit Login Attempts
jeba-limit-login-attempts
This is Jeba Limit Login Attempts wordpress plugin. Automatically lock the system for 30 minutes if a user attempts to login and fails after 3 tries.
Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection
admin-safety-guard
Protect your WP site from hackers for free. Limit logins, add 2FA, reCAPTCHA, block IPs, hide wp-login.php & track activity logs.
DoLogin Security Developer Profile
7 plugins · 8K total installs
How We Detect DoLogin Security
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dologin/assets/login.css/wp-content/plugins/dologin/assets/login.js/wp-content/plugins/dologin/assets/admin.jshttps://challenges.cloudflare.com/turnstile/v0/api.jsdologin/assets/login.css?ver=dologin/assets/login.js?ver=dologin/assets/admin.js?ver=HTML / DOM Fingerprints
cf-turnstiledologin-logodologin-processdologin-process-msgdata-sitekeydologindologin_admin/wp-json/dologin/v1/2fa/wp-json/dologin/v1/sms/wp-json/dologin/v1/test_sms/wp-json/dologin/v1/myip<img src="assets/shield.svg"class="dologin-logo"style="max-width:50px;max-height:37px;">