Email OTP Login with default login form Security & Risk Analysis

wordpress.org/plugins/email-otp-login-with-default-login-form

Adds email OTP (One-Time Password) verification after valid login credentials on the default wp-login.php form for added security.

40 active installs v1.0.3 PHP 7.2+ WP 5.0+ Updated Aug 5, 2025
email-verificationloginotpsecuritytwo-factor
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Email OTP Login with default login form Safe to Use in 2026?

Generally Safe

Score 100/100

Email OTP Login with default login form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The 'email-otp-login-with-default-login-form' plugin v1.0.3 demonstrates a strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the attack surface. Furthermore, the code signals indicate responsible development practices, with no dangerous functions, all SQL queries using prepared statements, and a high percentage of properly escaped output. The presence of nonce checks further reinforces good security hygiene.

Despite these positive indicators, the absence of any recorded vulnerabilities in its history, coupled with the lack of identified critical or high-severity taint flows, suggests a very low risk profile. However, the complete lack of capability checks on any entry points is a potential concern. While there are no direct entry points identified as unprotected, if any were to be introduced in future versions or through misconfiguration, they would lack proper authorization checks, presenting a latent risk. Overall, the plugin appears to be developed with security in mind, but future development should consider incorporating capability checks for enhanced robustness.

Key Concerns

  • No capability checks detected
Vulnerabilities
None known

Email OTP Login with default login form Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Email OTP Login with default login form Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
37 escaped
Nonce Checks
5
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped39 total outputs
Attack Surface

Email OTP Login with default login form Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionplugins_loadedemail-otp-login-with-default-login-form.php:21
actioninitincludes\class-email-otp-login.php:41
actionadmin_menuincludes\class-email-otp-login.php:42
actionadmin_initincludes\class-email-otp-login.php:43
filterauthenticateincludes\class-email-otp-login.php:44
actionlogin_initincludes\class-email-otp-login.php:45
actionlogin_footerincludes\class-email-otp-login.php:46
actionlogin_enqueue_scriptsincludes\class-email-otp-login.php:47
actionwp_enqueue_scriptsincludes\class-email-otp-login.php:48
actiontemplate_redirectincludes\class-email-otp-login.php:49
actioneolwdlf_render_otp_modalincludes\class-email-otp-login.php:50
actionwp_print_footer_scriptsincludes\class-email-otp-login.php:102
actionwp_print_footer_scriptsincludes\class-email-otp-login.php:122
actionwp_print_footer_scriptsincludes\class-email-otp-login.php:156
Maintenance & Trust

Email OTP Login with default login form Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 5, 2025
PHP min version7.2
Downloads683

Community Trust

Rating100/100
Number of ratings6
Active installs40
Developer Profile

Email OTP Login with default login form Developer Profile

Lalit Yadav

3 plugins · 50 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Email OTP Login with default login form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/email-otp-login-with-default-login-form/assets/css/otp-style.css
Version Parameters
email-otp-login-with-default-login-form/assets/css/otp-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
eolwdlf-login-style
JS Globals
eolwdlf_email_otp_login
FAQ

Frequently Asked Questions about Email OTP Login with default login form