
JuanMa JWT Auth Pro Security & Risk Analysis
wordpress.org/plugins/juanma-jwt-auth-proModern JWT authentication with refresh tokens - built for SPAs and mobile apps with enterprise-grade security.
Is JuanMa JWT Auth Pro Safe to Use in 2026?
Generally Safe
Score 100/100JuanMa JWT Auth Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "juanma-jwt-auth-pro" v1.2.1 demonstrates a generally good security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is a significant strength, indicating a limited attack surface. Furthermore, the code signals show a low number of potential risks, with no dangerous functions, critical or high severity taint flows, and a high percentage of properly escaped output.
The most notable concern from the static analysis is the presence of one SQL query that does not utilize prepared statements. While the total number of SQL queries is low, this represents a potential vulnerability to SQL injection if the query's inputs are not sufficiently sanitized elsewhere. The presence of file operations and capability checks, while not inherently risky, warrants attention to ensure proper implementation and access control.
The vulnerability history is exceptionally clean, with no known CVEs or recorded vulnerabilities. This suggests a well-maintained and secure codebase in the past. The overall picture is that of a plugin with a strong foundation and limited past security issues, but with a specific, albeit minor, risk related to raw SQL queries that should be addressed.
Key Concerns
- SQL query without prepared statements
JuanMa JWT Auth Pro Security Vulnerabilities
JuanMa JWT Auth Pro Code Analysis
SQL Query Safety
Output Escaping
JuanMa JWT Auth Pro Attack Surface
WordPress Hooks 10
Maintenance & Trust
JuanMa JWT Auth Pro Maintenance & Trust
Maintenance Signals
Community Trust
JuanMa JWT Auth Pro Alternatives
API Bearer Auth
api-bearer-auth
Access and refresh tokens based authentication plugin for the REST API.
HeadlessKey – JWT Auth
headlesskey-jwt-auth
A complete authentication solution for Headless WordPress applications using JWT, supporting Registration, SSO, RBAC, and advanced Security features.
JWT Authentication for WP REST API
jwt-authentication-for-wp-rest-api
Extends the WP REST API using JSON Web Tokens Authentication as an authentication method.
JWT Authentication for WP REST APIs
wp-rest-api-authentication
Secure and protect WordPress REST API from unauthorized access using JWT token, Basic Authentication, API Key, OAuth 2, or external token.
WP REST API Key Authentication
rest-api-key-authentication
A simple plugin to add API key-based authentication to the WordPress REST API. Manage multiple API keys and secure your REST API endpoints.
JuanMa JWT Auth Pro Developer Profile
1 plugin · 0 total installs
How We Detect JuanMa JWT Auth Pro
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/juanma-jwt-auth-pro/assets/css/jwt-auth-pro-admin.css/wp-content/plugins/juanma-jwt-auth-pro/assets/js/jwt-auth-pro-admin.js/wp-content/plugins/juanma-jwt-auth-pro/assets/js/jwt-auth-pro-admin.jsjuanma-jwt-auth-pro/assets/css/jwt-auth-pro-admin.css?ver=juanma-jwt-auth-pro/assets/js/jwt-auth-pro-admin.js?ver=HTML / DOM Fingerprints
jwt-auth-pro-settings-sectionjwt_auth_pro_admin_params/wp-json/jwt-auth-pro/v1/wp-json/jwt-auth-pro/v1/token/wp-json/jwt-auth-pro/v1/refresh