
KGR Login with Google Security & Risk Analysis
wordpress.org/plugins/kgr-login-with-googleLogin or register to WP usign Sign In with Google.
Is KGR Login with Google Safe to Use in 2026?
Generally Safe
Score 85/100KGR Login with Google has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The kgr-login-with-google plugin v1.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, not performing raw SQL queries, and limiting file operations. The presence of nonce and capability checks, although limited, is also a positive indicator. However, the plugin has a significant security concern due to its single AJAX handler lacking any authentication checks, presenting a direct entry point for potential attacks. The low percentage of properly escaped output suggests a risk of cross-site scripting (XSS) vulnerabilities, as data displayed to users may not be sufficiently sanitized. The absence of recorded vulnerabilities in its history is a strength, implying a generally stable codebase, but this should not overshadow the identified weaknesses. The lack of taint analysis results also makes it difficult to definitively rule out more complex injection vulnerabilities.
Overall, the most critical concern is the unprotected AJAX handler, which could be exploited by unauthenticated users to perform unintended actions within the plugin's functionality. Coupled with the insufficient output escaping, this plugin carries a moderate to high risk. While the lack of past vulnerabilities and its avoidance of raw SQL are commendable, the unprotected entry point and potential for XSS require immediate attention. Recommendations should focus on implementing robust authentication and authorization for all AJAX actions and ensuring all output is properly escaped to mitigate these risks.
Key Concerns
- Unprotected AJAX handler
- Low output escaping percentage
KGR Login with Google Security Vulnerabilities
KGR Login with Google Code Analysis
Output Escaping
KGR Login with Google Attack Surface
AJAX Handlers 1
WordPress Hooks 8
Maintenance & Trust
KGR Login with Google Maintenance & Trust
Maintenance Signals
Community Trust
KGR Login with Google Alternatives
Addonify – reCaptcha For EDD
addonify-recaptcha-for-edd
Addonify reCAPTCHA for EDD is a simple plugin that adds Google reCaptcha in Easy Digital Downloads login and registration forms.
Sign In With Socials (Google, Apple, Microsoft)
sign-in-with-essentials
Adds functionality "Sign in with" Google/Microsoft/Apple (beta version)
ThinkCaptcha – Login Captcha, Register Captcha & Checkout reCAPTCHA
thinkcaptcha
Secure WordPress & WooCommerce forms with Google reCAPTCHA. Stop spam, bots, and brute-force attacks effectively.
Titan Social Login
titan-social-login
One-click social login and account linking for Amazon, Facebook, Google, X (Twitter), and Microsoft.
Advanced Google reCAPTCHA
advanced-google-recaptcha
Captcha protection against spam comments & brute force login attacks using Google reCAPTCHA.
KGR Login with Google Developer Profile
4 plugins · 60 total installs
How We Detect KGR Login with Google
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<div style="margin: 0 6px 16px 0;"></div>