
Email Login Attempts Security & Risk Analysis
wordpress.org/plugins/email-login-attemptsThis plugin will send an email whenever a someone tries to login via the WordPress login page.
Is Email Login Attempts Safe to Use in 2026?
Generally Safe
Score 85/100Email Login Attempts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "email-login-attempts" v1.1.1 indicates a strong security posture with no detected dangerous functions, SQL injection risks (all queries use prepared statements), or output escaping issues. The plugin also has no file operations or external HTTP requests, and crucially, it exhibits zero-total entry points for attack, meaning there are no AJAX handlers, REST API routes, shortcodes, or cron events. This lack of an exposed attack surface is a significant strength. Furthermore, the vulnerability history is clean, with no known CVEs recorded.
While the absence of identified vulnerabilities and a zero attack surface are excellent signs, the complete absence of nonce and capability checks across all zero entry points is a notable observation. In a plugin with an attack surface, this would be a significant concern. However, given the zero entry points, the immediate risk from this specific finding is mitigated. The overall impression is of a plugin that has been developed with security in mind, and its lack of historical issues further reinforces this. The plugin's strengths lie in its minimal attack surface and its secure coding practices regarding data handling.
A balanced conclusion suggests this plugin is likely secure due to its design and lack of historical issues. The absence of checks on entry points is theoretically a weakness, but practically, with no entry points, this weakness remains dormant. Continued vigilance in its development would be prudent to maintain this strong security profile.
Key Concerns
- No nonce checks found
- No capability checks found
Email Login Attempts Security Vulnerabilities
Email Login Attempts Code Analysis
Email Login Attempts Attack Surface
WordPress Hooks 1
Maintenance & Trust
Email Login Attempts Maintenance & Trust
Maintenance Signals
Community Trust
Email Login Attempts Alternatives
WP Login Alerts by DigiP
wp-login-alerts
E-mails the site owner if anyone reaches or attempts to login to the site. Also shows the user names they attempt to login with.
Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall
limit-login-attempts-reloaded
Block excessive login attempts and protect your site against brute force attacks. Simple, yet powerful tools to improve site performance.
CloudSecure WP Security
cloudsecure-wp-security
管理画面とログインURLをサイバー攻撃から守る、国産・日本語対応のセキュリティ対策プラグインです。 かんたんな設定を行うだけで、不正アクセスや不正ログインからあなたのWordPressを保護します。
WP fail2ban – Advanced Security
wp-fail2ban
WP fail2ban uses fail2ban to protect your WordPress site.
Titan Anti-spam & Security
anti-spam
Block spam comments, defend against login attempts, and strengthen site security with anti-spam, brute-force protection, and two-factor authentication …
Email Login Attempts Developer Profile
2 plugins · 210 total installs
How We Detect Email Login Attempts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<!-- TODO: add admin page -->