
Fluistr Authentication Security & Risk Analysis
wordpress.org/plugins/fluistr-authenticationZero Password - One touch - Two Factor Authentication. Secure your WordPress site with a passwordless, simple and intuitive 2-factor authentication.
Is Fluistr Authentication Safe to Use in 2026?
Generally Safe
Score 100/100Fluistr Authentication has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The fluistr-authentication v1.2.4 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and has no known historical vulnerabilities. However, the plugin presents a notable concern regarding its attack surface, with 4 out of 7 AJAX handlers lacking authentication checks. This directly correlates with the taint analysis, which identified 3 critical severity flows with unsanitized paths. These findings suggest a significant risk of unauthorized access and potential manipulation through these unprotected AJAX endpoints. The lack of historical vulnerabilities might indicate diligent development or simply a lack of extensive security auditing or exploitation attempts targeting this specific plugin.
Key Concerns
- Unprotected AJAX handlers
- Taint flows with unsanitized paths (critical)
- Unescaped output detected
Fluistr Authentication Security Vulnerabilities
Fluistr Authentication Release Timeline
Fluistr Authentication Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Fluistr Authentication Attack Surface
AJAX Handlers 7
WordPress Hooks 45
Maintenance & Trust
Fluistr Authentication Maintenance & Trust
Maintenance Signals
Community Trust
Fluistr Authentication Alternatives
Authyo Passwordless Login
authyo-passwordless-login
Enable secure OTP login for WordPress with passwordless authentication using email-based one-time passwords (OTP) powered by Authyo.
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Wordfence Login Security
wordfence-login-security
Secure your website with Wordfence Login Security, providing two-factor authentication, login and registration CAPTCHA, and XML-RPC protection.
Titan Anti-spam & Security
anti-spam
Block spam comments, defend against login attempts, and strengthen site security with anti-spam, brute-force protection, and two-factor authentication …
Duo Two-Factor Authentication
duo-wordpress
Easily add Duo Security two-factor authentication to your WordPress website. Enable two-factor authentication for your admins and/or users.
Fluistr Authentication Developer Profile
4 plugins · 100K total installs
How We Detect Fluistr Authentication
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fluistr-authentication/modules/fluistr-login/assets/fluistr-login.css/wp-content/plugins/fluistr-authentication/modules/fluistr-login/assets/qrcode.min.js/wp-content/plugins/fluistr-authentication/modules/fluistr-login/assets/fluistr-login.min.js/wp-content/plugins/fluistr-authentication/modules/fluistr-login/assets/fluistr-login.min.jsfluistr-authentication/modules/fluistr-login/assets/fluistr-login.css?ver=fluistr-authentication/modules/fluistr-login/assets/qrcode.min.js?ver=fluistr-authentication/modules/fluistr-login/assets/fluistr-login.min.js?ver=HTML / DOM Fingerprints
data-plugin-name="fluistr-authentication"fluistr