
Email Login Attempts Security & Risk Analysis
wordpress.org/plugins/email-login-attemptsThis plugin will send an email whenever a someone tries to login via the WordPress login page.
Is Email Login Attempts Safe to Use in 2026?
Generally Safe
Score 85/100Email Login Attempts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "email-login-attempts" v1.1.1 indicates a strong security posture with no detected dangerous functions, SQL injection risks (all queries use prepared statements), or output escaping issues. The plugin also has no file operations or external HTTP requests, and crucially, it exhibits zero-total entry points for attack, meaning there are no AJAX handlers, REST API routes, shortcodes, or cron events. This lack of an exposed attack surface is a significant strength. Furthermore, the vulnerability history is clean, with no known CVEs recorded.
While the absence of identified vulnerabilities and a zero attack surface are excellent signs, the complete absence of nonce and capability checks across all zero entry points is a notable observation. In a plugin with an attack surface, this would be a significant concern. However, given the zero entry points, the immediate risk from this specific finding is mitigated. The overall impression is of a plugin that has been developed with security in mind, and its lack of historical issues further reinforces this. The plugin's strengths lie in its minimal attack surface and its secure coding practices regarding data handling.
A balanced conclusion suggests this plugin is likely secure due to its design and lack of historical issues. The absence of checks on entry points is theoretically a weakness, but practically, with no entry points, this weakness remains dormant. Continued vigilance in its development would be prudent to maintain this strong security profile.
Key Concerns
- No nonce checks found
- No capability checks found
Email Login Attempts Security Vulnerabilities
Email Login Attempts Release Timeline
Email Login Attempts Code Analysis
Email Login Attempts Attack Surface
WordPress Hooks 1
Maintenance & Trust
Email Login Attempts Maintenance & Trust
Maintenance Signals
Community Trust
Email Login Attempts Alternatives
WP Login Alerts by DigiP
wp-login-alerts
E-mails the site owner if anyone reaches or attempts to login to the site. Also shows the user names they attempt to login with.
GetIced Failed Login Alerts
geticed-failed-login-alerts
GetIced Failed Login Alerts is a lightweight WordPress security plugin that monitors failed login attempts and notifies administrators instantly.
Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention
limit-login-attempts-reloaded
WordPress login security with brute force protection, Two-factor authentication (2FA/MFA), firewall, IP/country blocking, and login monitoring
CloudSecure WP Security
cloudsecure-wp-security
CloudSecure WP Securityは、管理画面とログインURLをサイバー攻撃から守る、国産・日本語対応のセキュリティ対策プラグインです。 簡単な設定だけで、不正アクセスや不正ログインからWordPressを保護し、サイトのセキュリティを高めます。
WP Ghost (Hide My WP Ghost) – Security & Firewall
hide-my-wp
Hide and Secure WP paths with the complete WP security suite for Site Hardening. Includes 8G Firewall, Brute Force protection, and Passkeys.
Email Login Attempts Developer Profile
2 plugins · 210 total installs
How We Detect Email Login Attempts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<!-- TODO: add admin page -->