GateLink Client – Passwordless SSO & One‑Click Admin Access Security & Risk Analysis

wordpress.org/plugins/gatelink-client

Secure, zero‑config SSO for WordPress sites—validate HMAC‑signed links and log users into wp‑admin automatically.

0 active installs v1.8.3 PHP 8.0+ WP 6.3+ Updated Oct 17, 2025
admin-loginone-click-loginpasswordlesssecuritysingle-sign-on
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is GateLink Client – Passwordless SSO & One‑Click Admin Access Safe to Use in 2026?

Generally Safe

Score 100/100

GateLink Client – Passwordless SSO & One‑Click Admin Access has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "gatelink-client" v1.8.3 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code adheres to good security practices by demonstrating 100% proper output escaping and exclusively using prepared statements for SQL queries. The presence of nonce and capability checks, although limited in number, indicates an awareness of authentication and authorization mechanisms.

No critical or high severity taint flows were found, and the plugin has no recorded vulnerability history, suggesting it has been developed with security in mind and has not suffered from known exploits. This lack of historical vulnerabilities and a minimal attack surface are positive indicators. However, it's important to note that the analysis of 0 taint flows means there's no explicit evidence of vulnerabilities being *checked for* via taint analysis, only that none were *found*. The limited number of nonce and capability checks could potentially be a concern if the plugin were to introduce more complex functionalities in the future that interact with WordPress core or other plugins.

In conclusion, "gatelink-client" v1.8.3 appears to be a secure plugin with robust coding practices. The most significant strength is its effectively zero attack surface and clean code. The primary area for consideration is the potential for undiscovered vulnerabilities due to the absence of taint flow analysis results and the limited application of security checks, though the current data provides no direct evidence of this. The absence of any historical vulnerabilities is a strong positive signal.

Vulnerabilities
None known

GateLink Client – Passwordless SSO & One‑Click Admin Access Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

GateLink Client – Passwordless SSO & One‑Click Admin Access Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
42 escaped
Nonce Checks
3
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped42 total outputs
Attack Surface

GateLink Client – Passwordless SSO & One‑Click Admin Access Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedgatelink-client.php:48
actioninitincludes\class-plugin.php:31
actionrest_api_initincludes\class-plugin.php:32
actionadmin_menuincludes\class-plugin.php:33
actionadmin_enqueue_scriptsincludes\class-plugin.php:34
actionadmin_post_gatelink_client_allowincludes\class-plugin.php:35
actionadmin_post_gatelink_client_blockincludes\class-plugin.php:36
actionadmin_post_gatelink_client_deleteincludes\class-plugin.php:37
actiontemplate_redirectincludes\class-plugin.php:38
actionparse_requestincludes\class-plugin.php:40
filterquery_varsincludes\class-plugin.php:56
Maintenance & Trust

GateLink Client – Passwordless SSO & One‑Click Admin Access Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 17, 2025
PHP min version8.0
Downloads159

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

GateLink Client – Passwordless SSO & One‑Click Admin Access Developer Profile

NUMAN RASHEED

3 plugins · 550 total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect GateLink Client – Passwordless SSO & One‑Click Admin Access

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gatelink-client/assets/admin.css/wp-content/plugins/gatelink-client/assets/admin.js
Script Paths
/wp-content/plugins/gatelink-client/assets/admin.js
Version Parameters
gatelink-client/assets/admin.css?ver=gatelink-client/assets/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
gatelink-clientgatelink-copy-inputgatelink-copy-buttongatelink-connection-info-tablegatelink-fetch-managersgatelink-manual-addgatelink-stategatelink-state-active+2 more
Data Attributes
data-copy-text
JS Globals
gatelink_client_vars
REST Endpoints
/wp-json/gatelink/v1/trust-manager
FAQ

Frequently Asked Questions about GateLink Client – Passwordless SSO & One‑Click Admin Access