Easy Social Login Security & Risk Analysis

wordpress.org/plugins/easy-social-login

Easily integrate social login options into your WordPress site.

10 active installs v1.0.8 PHP 7.0+ WP 5.2+ Updated May 19, 2025
facebookgooglegoogle-one-tapsocial-loginwindows-live
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Easy Social Login Safe to Use in 2026?

Generally Safe

Score 100/100

Easy Social Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12mo ago
Risk Assessment

The "easy-social-login" v1.0.8 plugin exhibits a generally strong security posture, with no known historical vulnerabilities and excellent practices observed in its code. All SQL queries are properly prepared, all output is correctly escaped, and file operations are absent, significantly reducing common attack vectors. The absence of critical or high-severity taint flows further bolsters its security. However, a notable concern is the presence of an unprotected AJAX handler, which represents a direct entry point into the plugin without any authentication or authorization checks. While the plugin utilizes nonces and has some capability checks, the lack of checks on this specific AJAX endpoint presents a potential risk for unauthorized actions.

Key Concerns

  • Unprotected AJAX handler
Vulnerabilities
None known

Easy Social Login Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Easy Social Login Release Timeline

v1.0.9
v1.0.8Current
v1.0.7
v1.0.6
v1.0.5
v1.0.2
v1.0.1
Code Analysis
Analyzed Apr 16, 2026

Easy Social Login Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
403 escaped
Nonce Checks
5
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

100% escaped403 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
eslp_google_oauth_js_origins (modules/ESLP_Google_Module.php:370)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Easy Social Login Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_eslp_hide_message_timeincludes/eslp-easy-social-login-donate.php:78

Shortcodes 1

[eslp_easy_social_login] includes/eslp-easy-social-login-core.php:44
WordPress Hooks 49
actionplugins_loadedeasy-social-login.php:65
actionadmin_initincludes/eslp-easy-social-login-core.php:37
actioninitincludes/eslp-easy-social-login-core.php:40
actioninitincludes/eslp-easy-social-login-core.php:41
actionadmin_menuincludes/eslp-easy-social-login-core.php:47
actionadmin_noticesincludes/eslp-easy-social-login-core.php:50
actiontemplate_redirectincludes/eslp-easy-social-login-core.php:53
actionadmin_enqueue_scriptsincludes/eslp-easy-social-login-core.php:83
actionlogin_enqueue_scriptsincludes/eslp-easy-social-login-core.php:86
actionwoocommerce_before_customer_login_formincludes/eslp-easy-social-login-core.php:91
actionwoocommerce_checkout_initincludes/eslp-easy-social-login-core.php:92
actionlogin_formincludes/eslp-easy-social-login-core.php:381
actionregister_formincludes/eslp-easy-social-login-core.php:387
actionwoocommerce_checkout_initincludes/eslp-easy-social-login-core.php:419
actionwp_enqueue_scriptsincludes/eslp-easy-social-login-core.php:490
actionadmin_noticesincludes/eslp-easy-social-login-donate.php:53
actionadmin_initmodules/ESLP_Facebook_Module.php:27
filterquery_varsmodules/ESLP_Facebook_Module.php:33
actiontemplate_redirectmodules/ESLP_Facebook_Module.php:34
actionlogin_enqueue_scriptsmodules/ESLP_Facebook_Module.php:37
actionwoocommerce_login_formmodules/ESLP_Facebook_Module.php:38
actionwoocommerce_register_formmodules/ESLP_Facebook_Module.php:39
actionwoocommerce_checkout_initmodules/ESLP_Facebook_Module.php:41
actionlogin_formmodules/ESLP_Facebook_Module.php:227
actionregister_formmodules/ESLP_Facebook_Module.php:233
actionwoocommerce_checkout_initmodules/ESLP_Facebook_Module.php:265
actionadmin_initmodules/ESLP_Google_Module.php:23
filterquery_varsmodules/ESLP_Google_Module.php:29
actiontemplate_redirectmodules/ESLP_Google_Module.php:32
actionlogin_enqueue_scriptsmodules/ESLP_Google_Module.php:35
actionwoocommerce_checkout_initmodules/ESLP_Google_Module.php:38
actionlogin_formmodules/ESLP_Google_Module.php:223
actionregister_formmodules/ESLP_Google_Module.php:229
actionwoocommerce_checkout_initmodules/ESLP_Google_Module.php:261
actionwoocommerce_login_formmodules/ESLP_Google_Module.php:460
actionwoocommerce_register_formmodules/ESLP_Google_Module.php:461
actionadmin_initmodules/ESLP_WindowsLive_Module.php:27
filterquery_varsmodules/ESLP_WindowsLive_Module.php:33
actiontemplate_redirectmodules/ESLP_WindowsLive_Module.php:34
actionlogin_enqueue_scriptsmodules/ESLP_WindowsLive_Module.php:37
actionwoocommerce_login_formmodules/ESLP_WindowsLive_Module.php:38
actionwoocommerce_register_formmodules/ESLP_WindowsLive_Module.php:39
actionwoocommerce_checkout_initmodules/ESLP_WindowsLive_Module.php:41
actionlogin_formmodules/ESLP_WindowsLive_Module.php:208
actionregister_formmodules/ESLP_WindowsLive_Module.php:214
actionwoocommerce_checkout_initmodules/ESLP_WindowsLive_Module.php:246
filterallowed_redirect_hostsoauth/eslp-facebook-callback.php:190
filterallowed_redirect_hostsoauth/eslp-google-callback.php:246
filterallowed_redirect_hostsoauth/eslp-windowslive-callback.php:250
Maintenance & Trust

Easy Social Login Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 19, 2025
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Easy Social Login Developer Profile

Thiago Quadros

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy Social Login

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-social-login/assets/css/style.css/wp-content/plugins/easy-social-login/assets/css/eslp-admin.css/wp-content/plugins/easy-social-login/assets/js/eslp-admin.js/wp-content/plugins/easy-social-login/assets/js/eslp-frontend.js
Version Parameters
/wp-content/plugins/easy-social-login/assets/css/style.css?ver=/wp-content/plugins/easy-social-login/assets/css/eslp-admin.css?ver=/wp-content/plugins/easy-social-login/assets/js/eslp-admin.js?ver=/wp-content/plugins/easy-social-login/assets/js/eslp-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
eslp-social-login-buttoneslp-social-login-wrappereslp-social-login-linkeslp-social-login-icon
HTML Comments
<!-- Easy Social Login - Social Login Button --><!-- Easy Social Login - Custom Code Area --><!-- Easy Social Login - Social Login Form --><!-- Easy Social Login End - Social Login Form -->
Data Attributes
data-provider=data-site-id=data-redirect-uri=
JS Globals
window.eslp_frontend_datawindow.eslp_admin_data
Shortcode Output
[eslp_easy_social_login]
FAQ

Frequently Asked Questions about Easy Social Login