
Dolutech Passwordless Login Security & Risk Analysis
wordpress.org/plugins/dolutech-passwordless-loginPermite login seguro sem senha com tecnologia passwordless e autenticação de dois fatores (2FA) via TOTP.
Is Dolutech Passwordless Login Safe to Use in 2026?
Generally Safe
Score 100/100Dolutech Passwordless Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "dolutech-passwordless-login" v1.1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any reported vulnerabilities in its history is a significant positive indicator. Furthermore, the code demonstrates good security practices, with all SQL queries utilizing prepared statements, a high percentage of output being properly escaped, and a robust number of nonce and capability checks. The attack surface, while containing AJAX handlers, is fully protected by authentication checks, and there are no concerning taint analysis flows. The plugin also avoids the risks associated with bundled libraries and file operations.
However, the presence of a single external HTTP request represents a potential, albeit minor, point of concern. While the static analysis doesn't indicate any immediate risks from this request (e.g., lack of sanitization), it introduces an external dependency that could become a vector for future vulnerabilities if not properly managed or if the external service is compromised.
In conclusion, this plugin appears to be well-secured with strong adherence to fundamental WordPress security principles. The limited external interaction is a minor weakness that, in the absence of any historical vulnerabilities or critical code signals, does not significantly elevate the overall risk. Continued monitoring for any future CVEs or introduction of new external dependencies would be prudent.
Key Concerns
- External HTTP requests detected
Dolutech Passwordless Login Security Vulnerabilities
Dolutech Passwordless Login Code Analysis
Output Escaping
Data Flow Analysis
Dolutech Passwordless Login Attack Surface
AJAX Handlers 4
WordPress Hooks 13
Maintenance & Trust
Dolutech Passwordless Login Maintenance & Trust
Maintenance Signals
Community Trust
Dolutech Passwordless Login Alternatives
Wordfence Login Security
wordfence-login-security
Secure your website with Wordfence Login Security, providing two-factor authentication, login and registration CAPTCHA, and XML-RPC protection.
Keyless Auth – Login without Passwords
keyless-auth
Secure, passwordless authentication for WordPress. Your users login via magic email links – no passwords to remember or forget.
Login by Magic
magiclabs
Login by Magic plugin replaces the standard WordPress login form with one powered by Magic that enables passwordless email magic link login.
Llavero.io
llavero-io
Este plugin permite vincular las cuentas de usuario de WordPress con Llavero.io para tener un segundo factor de authenticación (2FA) en el login de lo …
PassClip Auth for WordPress
passclip-auth-for-wordpress
"PassClip Auth" provides strong and easy authentication. "PassClip Auth for WordPress" is the plugin to launch PassClip Auth to Wo …
Dolutech Passwordless Login Developer Profile
3 plugins · 40 total installs
How We Detect Dolutech Passwordless Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dolutech-passwordless-login/assets/css/style.css/wp-content/plugins/dolutech-passwordless-login/assets/js/admin-script.js/wp-content/plugins/dolutech-passwordless-login/assets/js/frontend-script.js/wp-content/plugins/dolutech-passwordless-login/assets/js/totp-script.jsdolutech-passwordless-login/assets/css/style.css?ver=dolutech-passwordless-login/assets/js/admin-script.js?ver=dolutech-passwordless-login/assets/js/frontend-script.js?ver=dolutech-passwordless-login/assets/js/totp-script.js?ver=HTML / DOM Fingerprints
dolupalo-login-form-wrapperdolupalo-admin-settings-pagedolupalo-qr-code-containerdolupalo-2fa-setup-message<!-- START Dolutech Passwordless Login Section --><!-- END Dolutech Passwordless Login Section --><!-- Dolutech Passwordless Login - QR Code Placeholder -->data-dolupalo-login-urldata-dolupalo-ajax-urldata-dolupalo-noncedolupalo_ajax_objectdolupalo_login_paramsdolupalo_totp_params/wp-json/dolutech-passwordless-login/v1/request-login/wp-json/dolutech-passwordless-login/v1/verify-token/wp-json/dolutech-passwordless-login/v1/enable-2fa/wp-json/dolutech-passwordless-login/v1/disable-2fa[dolutech_passwordless_login_form][dolutech_passwordless_login_status]