
Gatey – Login & SSO with Amazon Cognito Security & Risk Analysis
wordpress.org/plugins/gateyDrag-and-drop Amazon Cognito integration: 22-language screens, Single Sign-on, Multi-Factor Authentication, secure JWT tokens, and more.
Is Gatey – Login & SSO with Amazon Cognito Safe to Use in 2026?
Generally Safe
Score 100/100Gatey – Login & SSO with Amazon Cognito has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "gatey" v2.1.0 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and a high percentage of properly escaped output indicate good coding practices for preventing common vulnerabilities. Furthermore, the lack of known CVEs and a clean vulnerability history suggest a well-maintained and secure plugin over time. The limited attack surface, with only two shortcodes and no exposed AJAX or REST API endpoints without proper checks, further enhances its security.
However, a critical area for concern is the complete absence of nonce checks across all entry points. While the static analysis shows capability checks are present, the lack of nonces makes the plugin susceptible to Cross-Site Request Forgery (CSRF) attacks. An attacker could potentially trick a logged-in user into executing unintended actions through the shortcodes if the plugin performs any state-changing operations without these critical security measures. The presence of file operations and an external HTTP request, while not inherently insecure, warrants careful review to ensure these functionalities are implemented securely and do not introduce further vulnerabilities.
In conclusion, "gatey" v2.1.0 is a plugin with many positive security attributes, particularly in its handling of SQL and output escaping. The absence of historical vulnerabilities is a very good sign. The primary weakness lies in the missing nonce checks, which represents a significant security gap that should be addressed promptly. The plugin's overall security is good, but this single omission prevents it from being excellent.
Key Concerns
- Missing nonce checks on entry points
Gatey – Login & SSO with Amazon Cognito Security Vulnerabilities
Gatey – Login & SSO with Amazon Cognito Release Timeline
Gatey – Login & SSO with Amazon Cognito Code Analysis
Output Escaping
Gatey – Login & SSO with Amazon Cognito Attack Surface
Shortcodes 2
WordPress Hooks 32
Maintenance & Trust
Gatey – Login & SSO with Amazon Cognito Maintenance & Trust
Maintenance Signals
Community Trust
Gatey – Login & SSO with Amazon Cognito Alternatives
Login with Cognito
login-with-cognito
WordPress Login with Cognito plugin allows Login ( Single Sign-On ) to WordPress using AWS Cognito account credentials. You can Login to your WordPres …
Rainbow Secure – Advanced MFA & SSO Plugin
rainbow-secure
Boost your WordPress site’s security with advanced multi-layer MFA and seamless SSO integration.
Login for Google Apps
google-apps-login
Simple secure login and user management through your Google Workspace for WordPress (using oAuth2 and MFA if enabled).
OAuth Single Sign On – SSO (OAuth Client)
miniorange-login-with-eve-online-google-facebook
WordPress SSO (Single Sign On) with Azure, Azure B2C, Cognito, Okta, Classlink, Discord, Clever, Keycloak, OAuth & OpenID Providers [24/7 SUPPORT].
Log in with Google
login-with-google
Minimal plugin that allows WordPress users to log in using Google.
Gatey – Login & SSO with Amazon Cognito Developer Profile
2 plugins · 0 total installs
How We Detect Gatey – Login & SSO with Amazon Cognito
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gatey/main/index.js/wp-content/plugins/gatey/main/index.css/wp-content/plugins/gatey/blocks/index.js/wp-content/plugins/gatey/blocks/index.css/wp-content/plugins/gatey/main/index.js/wp-content/plugins/gatey/blocks/index.jsgatey/main/index.js?ver=gatey/main/index.css?ver=gatey/blocks/index.js?ver=gatey/blocks/index.css?ver=HTML / DOM Fingerprints
gatey-authenticator-formgatey-authenticator-footergatey-account-page-profilegatey-account-page-navbackward compatibilitydata-gatey-uiddata-gatey-screendata-gatey-colormodedata-gatey-languagedata-gatey-directiondata-gatey-totp+7 more__gateyGlobal.WpSuite.plugins.gatey__gateyGlobal.Gatey/wp-json/gatey/v1[gatey][gatey-account]