
Dovedi Security & Risk Analysis
wordpress.org/plugins/dovediTime-based One Time Password authentication for WordPress.
Is Dovedi Safe to Use in 2026?
Generally Safe
Score 85/100Dovedi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "dovedi" v1.1.1 plugin exhibits a strong security posture based on the provided static analysis. The plugin has no recorded vulnerabilities, which is a significant positive indicator. Furthermore, the code analysis reveals a clean bill of health: zero dangerous functions, all SQL queries utilizing prepared statements, a high percentage of properly escaped output, and a single nonce check, suggesting a conscious effort to implement basic security controls. The absence of file operations and external HTTP requests further minimizes potential attack vectors.
However, the taint analysis reveals a potential concern. While no critical or high severity flows were identified, the presence of three flows with unsanitized paths warrants attention. Although these might not directly translate to exploitable vulnerabilities in this specific context, they represent a potential weakness if the plugin's functionality were to evolve or interact with external data in the future. The lack of any recorded historical vulnerabilities is reassuring, suggesting either a history of secure development or a relatively new/obscure plugin with less exposure to sophisticated attacks.
In conclusion, "dovedi" v1.1.1 appears to be a well-developed plugin with good security practices in place, particularly concerning SQL and output sanitization. The primary area for improvement lies in addressing the identified unsanitized paths from the taint analysis to further harden the plugin against potential future threats. The overall risk is assessed as low.
Key Concerns
- Unsanitized paths in taint analysis
Dovedi Security Vulnerabilities
Dovedi Code Analysis
Output Escaping
Data Flow Analysis
Dovedi Attack Surface
WordPress Hooks 14
Maintenance & Trust
Dovedi Maintenance & Trust
Maintenance Signals
Community Trust
Dovedi Alternatives
Wordfence Login Security
wordfence-login-security
Secure your website with Wordfence Login Security, providing two-factor authentication, login and registration CAPTCHA, and XML-RPC protection.
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
Keyless Auth – Login without Passwords
keyless-auth
Secure, passwordless authentication for WordPress. Your users login via magic email links – no passwords to remember or forget.
Llavero.io
llavero-io
Este plugin permite vincular las cuentas de usuario de WordPress con Llavero.io para tener un segundo factor de authenticación (2FA) en el login de lo …
LoginShield for WordPress
loginshield
LoginShield for WordPress is the secure and convenient way to login to your WordPress site. It's easy to use and protects users against password …
Dovedi Developer Profile
6 plugins · 2K total installs
How We Detect Dovedi
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dovedi/assets/css/dovedi.css/wp-content/plugins/dovedi/assets/js/dovedi.js/wp-content/plugins/dovedi/assets/js/dovedi.jsdovedi/assets/css/dovedi.css?ver=dovedi/assets/js/dovedi.js?ver=HTML / DOM Fingerprints
totp-enablename="totp-authcode"id="totp-authcode"name="totp-key"name="totp-on"jQuery