
GS JWT Authentication for WP REST API Security & Risk Analysis
wordpress.org/plugins/gs-jwt-auth-and-otp-varificationExtends the WP REST API using JSON Web Tokens as an authentication method.
Is GS JWT Authentication for WP REST API Safe to Use in 2026?
Generally Safe
Score 85/100GS JWT Authentication for WP REST API has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the "gs-jwt-auth-and-otp-varification" v1.0.0 plugin exhibits a generally good security posture. The static analysis reveals a clean code base with no dangerous functions, all SQL queries utilizing prepared statements, and all outputs being properly escaped. Importantly, there are no identified taint flows, suggesting that user-supplied data is not being mishandled in critical ways. The plugin also has no external HTTP requests or file operations, reducing potential attack vectors.
However, a significant concern arises from the complete absence of nonce checks and capability checks. While the REST API routes do have permission callbacks, the lack of nonce checks on AJAX handlers (of which there are none in this version, but it's a common entry point) and the absence of any capability checks leaves the plugin vulnerable to various client-side attacks or unauthorized actions if any entry points were to be introduced without proper authorization mechanisms. The lack of any historical vulnerabilities is a positive sign, indicating a diligent approach to security in its development or a short history. Overall, the plugin is well-coded in terms of data handling and database interaction, but a lack of fundamental WordPress security practices like nonce and capability checks represents a notable weakness.
Key Concerns
- Missing nonce checks on AJAX handlers
- Missing capability checks
GS JWT Authentication for WP REST API Security Vulnerabilities
GS JWT Authentication for WP REST API Code Analysis
SQL Query Safety
Output Escaping
GS JWT Authentication for WP REST API Attack Surface
REST API Routes 7
WordPress Hooks 6
Maintenance & Trust
GS JWT Authentication for WP REST API Maintenance & Trust
Maintenance Signals
Community Trust
GS JWT Authentication for WP REST API Alternatives
User Data Fields For JWT Authentication
custom-fields-for-jwt-authentication-for-wp-rest-api
Wordpress is a good content mangement system for building websites, but it will be better if you build like mobile apps,
JWT Authentication for WP REST API
jwt-authentication-for-wp-rest-api
Extends the WP REST API using JSON Web Tokens Authentication as an authentication method.
Two Factor
two-factor
Enable Two-Factor Authentication (2FA) using time-based one-time passwords (TOTP), Universal 2nd Factor (U2F), email, and backup verification codes.
Google Authenticator
google-authenticator
Google Authenticator for your WordPress blog.
JWT Authentication for WP REST APIs
wp-rest-api-authentication
Secure and protect WordPress REST API from unauthorized access using JWT token, Basic Authentication, API Key, OAuth 2, or external token.
GS JWT Authentication for WP REST API Developer Profile
2 plugins · 10 total installs
How We Detect GS JWT Authentication for WP REST API
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
/gs-jwt/v1/login/gs-jwt/v1/token/validate/gs-jwt/v1/get-otp/gs-jwt/v1/verify-otp/gs-jwt/v1/register_user/gs-jwt/v1/register_userbymobile/gs-jwt/v1/login_test