
DoLogin Security Security & Risk Analysis
wordpress.org/plugins/dologinEasy Login. 2FA login. Passwordless login. Cloudflare Turnstile reCAPTCHA. GeoLocation (Continent/Country/City)/IP range to limit login attempts.
Is DoLogin Security Safe to Use in 2026?
Generally Safe
Score 98/100DoLogin Security has a strong security track record. Known vulnerabilities have been patched promptly.
The "dologin" v4.3 plugin presents a mixed security posture. While it shows strengths in its SQL query handling, with a high percentage of prepared statements, and a lack of bundled libraries, several concerning areas emerge from the static analysis and historical vulnerability data. The significant number of flows with unsanitized paths, particularly those flagged as high severity in the taint analysis, alongside a considerable portion of output not being properly escaped, indicates a high risk of cross-site scripting (XSS) and other injection vulnerabilities. Furthermore, the presence of REST API routes without permission callbacks creates direct attack vectors that could be leveraged by unauthenticated users. The plugin's history of four known CVEs, including a high-severity one, across common vulnerability types like Missing Authorization and XSS, suggests a recurring pattern of insecure coding practices. Despite the absence of currently unpatched CVEs, the ongoing risk associated with these historical issues and the identified static analysis concerns warrants caution. The combination of unprotected entry points and a history of security flaws necessitates careful consideration before deployment.
Key Concerns
- High severity taint flows
- Unsanitized paths
- Low percentage of properly escaped output
- REST API routes without permission callbacks
- Presence of high severity past CVE
- History of medium severity past CVEs
DoLogin Security Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
DoLogin Security <= 3.7.1 - Missing Authorization via REST Endpoints
DoLogin Security <= 3.7 - Missing Authorization on Dashboard Widget
DoLogin Security <= 3.6 - Unauthenticated Stored Cross-Site Scripting
DoLogin Security <= 3.6 - IP Address Spoofing
DoLogin Security Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
DoLogin Security Attack Surface
REST API Routes 4
WordPress Hooks 32
Maintenance & Trust
DoLogin Security Maintenance & Trust
Maintenance Signals
Community Trust
DoLogin Security Alternatives
Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall
limit-login-attempts-reloaded
Block excessive login attempts and protect your site against brute force attacks. Simple, yet powerful tools to improve site performance.
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Defender Security – Malware Scanner, Login Security & Firewall
defender-security
WordPress security plugin with malware scanner, IP blocking, audit logs, antivirus scans, firewall, 2FA, brute force login security, and more.
Wordfence Login Security
wordfence-login-security
Secure your website with Wordfence Login Security, providing two-factor authentication, login and registration CAPTCHA, and XML-RPC protection.
BulletProof Security
bulletproof-security
WordPress Security Protection: Malware scanner, Firewall, Login Security, DB Backup, Anti-Spam...
DoLogin Security Developer Profile
6 plugins · 8K total installs
How We Detect DoLogin Security
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dologin/assets/login.css/wp-content/plugins/dologin/assets/login.js/wp-content/plugins/dologin/assets/admin.jshttps://challenges.cloudflare.com/turnstile/v0/api.jsdologin/assets/login.css?ver=dologin/assets/login.js?ver=dologin/assets/admin.js?ver=HTML / DOM Fingerprints
cf-turnstiledologin-logodologin-processdologin-process-msgdata-sitekeydologindologin_admin/wp-json/dologin/v1/2fa/wp-json/dologin/v1/sms/wp-json/dologin/v1/test_sms/wp-json/dologin/v1/myip<img src="assets/shield.svg"class="dologin-logo"style="max-width:50px;max-height:37px;">