
Fingerlogin Security & Risk Analysis
wordpress.org/plugins/fingerloginFingerlogin enable Fingerprint biometric login authentication to sign into websites and services.
Is Fingerlogin Safe to Use in 2026?
Generally Safe
Score 85/100Fingerlogin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the "fingerlogin" plugin v2.0 exhibits a seemingly strong security posture with no directly identified vulnerabilities or dangerous code practices. The absence of known CVEs and the 100% usage of prepared statements for SQL queries are positive indicators. The plugin also has a minimal attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed. Furthermore, the taint analysis shows no identified flows with unsanitized paths, which is a very encouraging sign. The presence of file operations and external HTTP requests, however, warrants careful scrutiny to ensure they are implemented securely and don't introduce unexpected risks. The significant concern stems from the complete lack of nonce checks and capability checks. This means that even if the plugin has no exposed entry points, any authenticated user could potentially interact with its functionalities without proper authorization verification, leading to potential privilege escalation or unauthorized actions if any logic flaws exist that are not immediately apparent from static analysis alone. The 75% output escaping also indicates a potential for cross-site scripting (XSS) vulnerabilities in the remaining unescaped outputs.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Some output not properly escaped
Fingerlogin Security Vulnerabilities
Fingerlogin Release Timeline
Fingerlogin Code Analysis
Output Escaping
Fingerlogin Attack Surface
WordPress Hooks 6
Maintenance & Trust
Fingerlogin Maintenance & Trust
Maintenance Signals
Community Trust
Fingerlogin Alternatives
RapID Secure Login
rapid-secure-login
RapID Secure Login (RapID-SL) is a simple and convenient authentication plugin.
Auth Armor – Passwordless Login
auth-armor-passwordless-login
Login using your phone without passwords! More secure, faster and best of all, nothing to remember or type in!
Multidots Passkey Login – Passwordless Login for WordPress
multidots-passkey-login
Passwordless login for WordPress with Passkeys. Enable Touch ID, Face ID, and security keys for seamless, phishing-resistant authentication.
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Limit Login Attempts
limit-login-attempts
Limit rate of login attempts, including by way of cookies, for each IP. Fully customizable.
Fingerlogin Developer Profile
1 plugin · 10 total installs
How We Detect Fingerlogin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fingerlogin/logo28.png/wp-content/plugins/fingerlogin/loginbtn.pngHTML / DOM Fingerprints
fingerlogin_enabledfingerlogin_registerfingerlogin-settings-group/wp-json/fingerlogin/login<a href="api/fingerlogin/login" title="Login with Fingerlogin">
<img src="" width="152px" height="34px" alt="