
JWT Authenticator Security & Risk Analysis
wordpress.org/plugins/jwt-authenticatorThis plugin integrates JWT authentication and automates user creation.
Is JWT Authenticator Safe to Use in 2026?
Generally Safe
Score 85/100JWT Authenticator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "jwt-authenticator" plugin v1.0 exhibits a mixed security posture. A significant concern is the presence of a REST API route that lacks any permission callback, creating a direct and unprotected entry point into the WordPress application. While the static analysis shows no dangerous functions, 100% prepared SQL statements, and high output escaping, the absence of capability checks on the identified REST API route is a critical oversight. The plugin's vulnerability history is clean, with no known CVEs, which is a positive indicator of general stability. However, this lack of historical vulnerabilities should not overshadow the immediate risk posed by the unprotected REST API endpoint, which could potentially be exploited by unauthenticated attackers.
Key Concerns
- Unprotected REST API route
- Missing capability checks on entry points
JWT Authenticator Security Vulnerabilities
JWT Authenticator Release Timeline
JWT Authenticator Code Analysis
Output Escaping
JWT Authenticator Attack Surface
REST API Routes 1
WordPress Hooks 4
Maintenance & Trust
JWT Authenticator Maintenance & Trust
Maintenance Signals
Community Trust
JWT Authenticator Alternatives
AH JWT Auth
ah-jwt-auth
This plugin allows sign in to WordPress using a JSON Web Token (JWT) contained in a HTTP Header.
Twelve Legs Marketing SSO
twelve-legs-marketing-sso
Single sign-on plugin for WordPress that accepts RS256 JWTs from the TWL SSO application for secure authentication.
Login for Google Apps
google-apps-login
Simple secure login and user management through your Google Workspace for WordPress (using oAuth2 and MFA if enabled).
JWT Auth – WordPress JSON Web Token Authentication
jwt-auth
Create JSON Web Token Authentication in WordPress.
Log in with Google
login-with-google
Minimal plugin that allows WordPress users to log in using Google.
JWT Authenticator Developer Profile
2 plugins · 20 total installs
How We Detect JWT Authenticator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
/wp-json/jwt-auth/v1/callback