
Easy Secure Login – Google One Tap & Sign-In Security & Risk Analysis
wordpress.org/plugins/easy-secure-loginEliminate passwords and secure your site with Google. This plugin replaces WordPress login with a secure Google Sign-In button and frictionless Google …
Is Easy Secure Login – Google One Tap & Sign-In Safe to Use in 2026?
Generally Safe
Score 100/100Easy Secure Login – Google One Tap & Sign-In has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'easy-secure-login' plugin version 2.2.1 demonstrates a generally good security posture based on the static analysis. The absence of known CVEs and a clean vulnerability history are significant strengths. The code also shows strong adherence to secure coding practices, with a high percentage of properly escaped outputs, no direct SQL queries that aren't prepared, and a good number of nonce and capability checks.
However, there are areas that warrant attention. The presence of two taint analysis flows with unsanitized paths, even without critical or high severity, indicates a potential for vulnerabilities if these flows are ever exploited. These represent the most concrete risk identified in the static analysis. Furthermore, the plugin makes three external HTTP requests, which, while not inherently insecure, represent an external dependency that could introduce risks if the remote endpoints are compromised or if data is not handled securely during transmission.
In conclusion, while the plugin has a strong foundation with no known vulnerabilities and good internal security practices, the two unsanitized taint flows are a notable weakness that requires further investigation and potential remediation. The external HTTP requests are a minor concern that should be monitored.
Key Concerns
- Flows with unsanitized paths (2)
- External HTTP requests (3)
Easy Secure Login – Google One Tap & Sign-In Security Vulnerabilities
Easy Secure Login – Google One Tap & Sign-In Release Timeline
Easy Secure Login – Google One Tap & Sign-In Code Analysis
Output Escaping
Data Flow Analysis
Easy Secure Login – Google One Tap & Sign-In Attack Surface
AJAX Handlers 1
WordPress Hooks 33
Maintenance & Trust
Easy Secure Login – Google One Tap & Sign-In Maintenance & Trust
Maintenance Signals
Community Trust
Easy Secure Login – Google One Tap & Sign-In Alternatives
Wapu Auth – Google Social Login for WordPress & WooCommerce
wapu-auth-social-login
Google Social Login for WordPress & WooCommerce -- free. Let users register and login with their Google account in one click. No passwords, no forms.
Temporary Login Without Password
temporary-login-without-password
Create self-expiring, temporary admin accounts. Easily share direct login links (no need for username/password) with your developers or editors.
LoginWP (Formerly Peter's Login Redirect)
peters-login-redirect
Redirect users to different locations after they log in, log out and register based on different conditions.
Temporary Login
temporary-login
Create a secure, temporary URL for easy access to your WP admin.
FluentAuth – The Ultimate Authorization & Security Plugin for WordPress
fluent-security
Enhance the Security and User Experience of Your Site with Login/Signup Security, Two-Factor Email Authentication, Social Logins and more...
Easy Secure Login – Google One Tap & Sign-In Developer Profile
1 plugin · 20 total installs
How We Detect Easy Secure Login – Google One Tap & Sign-In
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easy-secure-login/assets/css/bootstrap.min.css/wp-content/plugins/easy-secure-login/assets/css/eslgp-admin.css/wp-content/plugins/easy-secure-login/assets/css/frontend.css/wp-content/plugins/easy-secure-login/assets/js/admin.js/wp-content/plugins/easy-secure-login/assets/js/frontend.js/wp-content/plugins/easy-secure-login/assets/js/google-one-tap.js/wp-content/plugins/easy-secure-login/assets/js/admin.js/wp-content/plugins/easy-secure-login/assets/js/frontend.js/wp-content/plugins/easy-secure-login/assets/js/google-one-tap.jseasy-secure-login/assets/css/bootstrap.min.css?ver=easy-secure-login/assets/css/eslgp-admin.css?ver=easy-secure-login/assets/css/frontend.css?ver=easy-secure-login/assets/js/admin.js?ver=easy-secure-login/assets/js/frontend.js?ver=easy-secure-login/assets/js/google-one-tap.js?ver=HTML / DOM Fingerprints
eslgp-admin-wrapeslgp-settings-formeslgp-google-login-buttoneslgp-one-tap-container<!-- Easy Secure Login Admin Settings --><!-- Easy Secure Login Frontend Content -->data-client-iddata-redirect-uridata-login-urleslgp_admin_paramseslgp_frontend_paramsgoogleOneTap/wp-json/eslgp/v1/auth[easy_secure_login_button][easy_secure_login_one_tap]