
FluentAuth – The Ultimate Authorization & Security Plugin for WordPress Security & Risk Analysis
wordpress.org/plugins/fluent-securityEnhance the Security and User Experience of Your Site with Login/Signup Security, Two-Factor Email Authentication, Social Logins and more...
Is FluentAuth – The Ultimate Authorization & Security Plugin for WordPress Safe to Use in 2026?
Generally Safe
Score 98/100FluentAuth – The Ultimate Authorization & Security Plugin for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The "fluent-security" v2.1.1 plugin exhibits a mixed security posture. While it demonstrates good practices with a high percentage of prepared SQL statements and properly escaped output, significant concerns arise from its attack surface and vulnerability history. The presence of 4 AJAX handlers without authentication checks presents a considerable risk, as these could be exploited by unauthenticated users to perform unintended actions or expose sensitive information. The taint analysis, although showing no critical or high severity flows, did reveal 6 flows with unsanitized paths, indicating potential, albeit low-severity, vulnerabilities if not properly handled downstream. The plugin's vulnerability history shows 2 medium-severity CVEs, which, while currently patched, suggest a past susceptibility to certain types of attacks. The last vulnerability being in late 2025 is unusual and might indicate a data anomaly, but the pattern of medium severity issues warrants attention for future development. The plugin's strengths lie in its code hygiene regarding SQL and output, but the unprotected AJAX endpoints are a critical oversight that needs immediate remediation.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths detected
- Medium severity CVEs in history
FluentAuth – The Ultimate Authorization & Security Plugin for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
FluentAuth - Auth Security Plugin <= 2.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'fluent_auth_reset_password' Shortcode
FluentAuth <= 1.0.1 - IP Spoofing to Protection Mechanism Bypass
FluentAuth – The Ultimate Authorization & Security Plugin for WordPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
FluentAuth – The Ultimate Authorization & Security Plugin for WordPress Attack Surface
AJAX Handlers 8
Shortcodes 7
WordPress Hooks 71
Scheduled Events 4
Maintenance & Trust
FluentAuth – The Ultimate Authorization & Security Plugin for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
FluentAuth – The Ultimate Authorization & Security Plugin for WordPress Alternatives
Disable XML-RPC-API
disable-xml-rpc-api
A simple and lightweight plugin to disable XML-RPC API, X-Pingback and pingback-ping in WordPress 3.5+ for a faster and more secure website
Disable XML-RPC Pingback
disable-xml-rpc-pingback
Stops abuse of your site's XML-RPC by simply removing some methods used by attackers. While you can use the rest of XML-RPC methods.
Inactive Logout
inactive-logout
Automatically logout idle user sessions, with logout redirections and concurrent limit logins all in one place.
Remove & Disable XML-RPC Pingback
remove-xmlrpc-pingback-ping
Prevent pingback, XML-RPC and denial of service DDOS attacks by disabling the XML-RPC pingback functionality.
DoLogin Security
dologin
Easy Login. 2FA login. Passwordless login. Cloudflare Turnstile reCAPTCHA. GeoLocation (Continent/Country/City)/IP range to limit login attempts.
FluentAuth – The Ultimate Authorization & Security Plugin for WordPress Developer Profile
17 plugins · 1.3M total installs
How We Detect FluentAuth – The Ultimate Authorization & Security Plugin for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fluent-security/dist/admin/app.js/wp-content/plugins/fluent-security/dist/libs/diff.js/wp-content/plugins/fluent-security/dist/admin/app.js/wp-content/plugins/fluent-security/dist/libs/diff.jsfluent-security/dist/admin/app.js?ver=fluent-security/dist/libs/diff.js?ver=HTML / DOM Fingerprints
fluent_auth_admin_appdata-nonce="wp_rest"data-namespace="fluent-auth"data-version="1"fluentAuthAdmin/wp-json/fluent-auth