Gatey – Login & SSO with Amazon Cognito Security & Risk Analysis

wordpress.org/plugins/gatey

Drag-and-drop Amazon Cognito integration: 22-language screens, Single Sign-on, Multi-Factor Authentication, secure JWT tokens, and more.

0 active installs v2.1.5 PHP 8.1+ WP 6.7+ Updated Apr 2, 2026
awscognitologinmfasso
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gatey – Login & SSO with Amazon Cognito Safe to Use in 2026?

Generally Safe

Score 100/100

Gatey – Login & SSO with Amazon Cognito has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "gatey" v2.1.0 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and a high percentage of properly escaped output indicate good coding practices for preventing common vulnerabilities. Furthermore, the lack of known CVEs and a clean vulnerability history suggest a well-maintained and secure plugin over time. The limited attack surface, with only two shortcodes and no exposed AJAX or REST API endpoints without proper checks, further enhances its security.

However, a critical area for concern is the complete absence of nonce checks across all entry points. While the static analysis shows capability checks are present, the lack of nonces makes the plugin susceptible to Cross-Site Request Forgery (CSRF) attacks. An attacker could potentially trick a logged-in user into executing unintended actions through the shortcodes if the plugin performs any state-changing operations without these critical security measures. The presence of file operations and an external HTTP request, while not inherently insecure, warrants careful review to ensure these functionalities are implemented securely and do not introduce further vulnerabilities.

In conclusion, "gatey" v2.1.0 is a plugin with many positive security attributes, particularly in its handling of SQL and output escaping. The absence of historical vulnerabilities is a very good sign. The primary weakness lies in the missing nonce checks, which represents a significant security gap that should be addressed promptly. The plugin's overall security is good, but this single omission prevents it from being excellent.

Key Concerns

  • Missing nonce checks on entry points
Vulnerabilities
None known

Gatey – Login & SSO with Amazon Cognito Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Gatey – Login & SSO with Amazon Cognito Release Timeline

v2.1.5Current
v2.1.4
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.15
v2.0.14
v2.0.13
v2.0.12
v2.0.11
v2.0.10
v2.0.9
v2.0.8
v2.0.7
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.2
Code Analysis
Analyzed Mar 17, 2026

Gatey – Login & SSO with Amazon Cognito Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
65 escaped
Nonce Checks
0
Capability Checks
5
File Operations
2
External Requests
1
Bundled Libraries
0

Output Escaping

97% escaped67 total outputs
Attack Surface

Gatey – Login & SSO with Amazon Cognito Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[gatey] gatey.php:84
[gatey-account] gatey.php:85
WordPress Hooks 32
filterauth_cookie_expirationadmin\admin.php:71
filterparent_fileadmin\admin.php:99
filtersubmenu_fileadmin\admin.php:100
filtermanage_edit-wp_block_columnsadmin\admin.php:102
actionmanage_wp_block_posts_custom_columnadmin\admin.php:103
actionadmin_enqueue_scriptsadmin\admin.php:104
actionrest_api_initadmin\admin.php:528
filterauth_cookie_expirationadmin\index.php:86
filterparent_fileadmin\index.php:114
filtersubmenu_fileadmin\index.php:115
filtermanage_edit-wp_block_columnsadmin\index.php:117
actionmanage_wp_block_posts_custom_columnadmin\index.php:118
actionadmin_enqueue_scriptsadmin\index.php:119
actionrest_api_initadmin\index.php:532
actionelementor/elements/categories_registeredgatey-elementor-widgets.php:34
actionelementor/widgets/registergatey-elementor-widgets.php:382
actionwp_enqueue_scriptsgatey.php:76
actionadmin_initgatey.php:77
actionelementor/preview/after_enqueue_scriptsgatey.php:78
actionadmin_menugatey.php:81
filterblock_categories_allgatey.php:88
filterlogin_urlgatey.php:91
filterlogout_urlgatey.php:92
actionelementor/initgatey.php:102
actioninitgatey.php:372
actionplugins_loadedgatey.php:373
actionwp_enqueue_scriptshub-for-wpsuiteio\index.php:64
actionadmin_inithub-for-wpsuiteio\index.php:65
actionelementor/preview/after_enqueue_scriptshub-for-wpsuiteio\index.php:66
actionadmin_enqueue_scriptshub-for-wpsuiteio\index.php:148
actionrest_api_inithub-for-wpsuiteio\index.php:308
actionadmin_menuhub-loader.php:61
Maintenance & Trust

Gatey – Login & SSO with Amazon Cognito Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 2, 2026
PHP min version8.1
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Gatey – Login & SSO with Amazon Cognito Developer Profile

Smart Cloud Solutions Inc.

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gatey – Login & SSO with Amazon Cognito

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gatey/main/index.js/wp-content/plugins/gatey/main/index.css/wp-content/plugins/gatey/blocks/index.js/wp-content/plugins/gatey/blocks/index.css
Script Paths
/wp-content/plugins/gatey/main/index.js/wp-content/plugins/gatey/blocks/index.js
Version Parameters
gatey/main/index.js?ver=gatey/main/index.css?ver=gatey/blocks/index.js?ver=gatey/blocks/index.css?ver=

HTML / DOM Fingerprints

CSS Classes
gatey-authenticator-formgatey-authenticator-footergatey-account-page-profilegatey-account-page-nav
HTML Comments
backward compatibility
Data Attributes
data-gatey-uiddata-gatey-screendata-gatey-colormodedata-gatey-languagedata-gatey-directiondata-gatey-totp+7 more
JS Globals
__gateyGlobal.WpSuite.plugins.gatey__gateyGlobal.Gatey
REST Endpoints
/wp-json/gatey/v1
Shortcode Output
[gatey][gatey-account]
FAQ

Frequently Asked Questions about Gatey – Login & SSO with Amazon Cognito