
Hellō Login Security & Risk Analysis
wordpress.org/plugins/hello-loginFree and simple to setup plugin provides registration and login with the Hellō Wallet. Users choose from popular social login, email, or phone.
Is Hellō Login Safe to Use in 2026?
Generally Safe
Score 85/100Hellō Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hello-login" plugin v1.5.4 exhibits a generally good security posture based on the provided static analysis. The plugin demonstrates a strong adherence to WordPress security best practices, with a high percentage of properly escaped output and a robust use of capability checks. The absence of dangerous functions and a clean vulnerability history further contribute to its positive security assessment. However, the presence of two unsanitized paths in the taint analysis warrants attention. While these flows did not reach a critical or high severity, unsanitized paths can be a precursor to vulnerabilities if user-supplied data is not handled appropriately, especially in conjunction with file operations or external HTTP requests.
The plugin has no recorded CVEs, which is a significant strength and suggests a history of secure development. The limited attack surface, with no unprotected entry points, is also commendable. The moderate use of prepared statements for SQL queries is acceptable but could be improved. Overall, "hello-login" appears to be a relatively secure plugin with a few areas for potential enhancement, primarily around input sanitization for identified unsanitized paths.
Key Concerns
- Unsanitized paths in taint analysis
- SQL queries with only 50% prepared statements
Hellō Login Security Vulnerabilities
Hellō Login Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Hellō Login Attack Surface
Shortcodes 2
WordPress Hooks 28
Scheduled Events 1
Maintenance & Trust
Hellō Login Maintenance & Trust
Maintenance Signals
Community Trust
Hellō Login Alternatives
OpenID Connect Generic Client
daggerhart-openid-connect-generic
A simple client that provides SSO or opt-in authentication against a generic OAuth2 Server implementation.
Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall
limit-login-attempts-reloaded
Block excessive login attempts and protect your site against brute force attacks. Simple, yet powerful tools to improve site performance.
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Loginizer
loginizer
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Security Optimizer – The All-In-One Protection Plugin
sg-security
Secure your WordPress site from brute-force attacks, threats, malware, and bots. Free to use and easy to set up.
Hellō Login Developer Profile
1 plugin · 10 total installs
How We Detect Hellō Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
hello-login/style.css?ver=hello-login/js/hello-login-admin.js?ver=hello-login/js/hello-login-frontend.js?ver=HTML / DOM Fingerprints
hello-login-adminhello-login-settings-pagehello-login-fieldhello-login-fieldshello-login-tabshello-login-tabhello-login-tab-contenthello-login-button+2 more<!-- Settings --><!-- TODO: consider adding filter for network_admin_plugin_action_links_... as well. --><!-- Hello_Login class. --><!-- Singleton instance of self -->+34 moredata-hello-login-client-iddata-hello-login-redirect-urihelloLoginFrontend/wp-json/hello-login/v1/callback/wp-json/hello-login/v1/unlink/wp-json/hello-login/v1/quickstart/wp-json/hello-login/v1/start/wp-json/hello-login/v1/event[hello_login_auth_url]