
Heateor Login – Social Login Plugin Security & Risk Analysis
wordpress.org/plugins/heateor-loginAllow your website visitors to login to your website via their Facebook accounts
Is Heateor Login – Social Login Plugin Safe to Use in 2026?
Generally Safe
Score 99/100Heateor Login – Social Login Plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The 'heateor-login' plugin exhibits a mixed security posture. While it generally uses prepared statements for SQL queries and has a moderate number of file operations and external requests, there are significant concerns regarding input sanitization and authentication. The static analysis reveals one unprotected AJAX handler, which presents a direct attack vector. Furthermore, 33% of output is not properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is mishandled. The taint analysis shows one high-severity flow, likely related to the unprotected entry point or unsanitized output, which is a critical concern. The vulnerability history, while showing no currently unpatched CVEs, does list a past medium-severity XSS vulnerability, reinforcing the risk associated with input handling. The lack of nonce checks on the identified unprotected AJAX handler is also a notable weakness. Overall, the plugin has several areas needing immediate attention to improve its security.
Key Concerns
- Unprotected AJAX handler
- Low percentage of properly escaped output
- High severity taint flow detected
- No nonce checks on entry points
- Past medium severity XSS vulnerability
Heateor Login – Social Login Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Heateor Login – Social Login Plugin <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Heateor Login – Social Login Plugin Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Heateor Login – Social Login Plugin Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 26
Maintenance & Trust
Heateor Login – Social Login Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Heateor Login – Social Login Plugin Alternatives
Social Login
oa-social-login
With Social Login your users can login, register and comment with 40+ Social Networks. Maintenance Free. Uptime Guarantee. Fulltime devs
UsersWP – Social Login
userswp-social-login
Social Login addon for UsersWP.
WP Social AutoConnect
wp-fb-autoconnect
A lightweight but powerful Facebook login plugin, easy to setup and transparent to new and returning users alike. Supports Buddypress.
Happy Social Login
happy-social-login
Enables user authentication through various social media accounts. Login through Google, Facebook, LinkedIn, GitHub and more.
NS Social Login
ns-social-login
This plugin add butto facebook login to your login page
Heateor Login – Social Login Plugin Developer Profile
6 plugins · 107K total installs
How We Detect Heateor Login – Social Login Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/heateor-login/css/style.css/wp-content/plugins/heateor-login/js/script.js/wp-content/plugins/heateor-login/js/script.jsheateor-login/css/style.css?ver=heateor-login/js/script.js?ver=HTML / DOM Fingerprints
heateor_fbl_social_login_titleheateor_fbl_login_containerheateor_fbl_login_ulheateorFblLoginheateorFblFacebookBackgroundheateorFblFacebookLoginheateorFblFacebookLogoContainerheateorFblLoginSvg+4 moreheateor_fbl_gdpr_consentheateorFblLoginContainer