
Lana Security Security & Risk Analysis
wordpress.org/plugins/lana-securitySecurity plugin to protect website with login captcha, hide version number and security monitor
Is Lana Security Safe to Use in 2026?
Generally Safe
Score 85/100Lana Security has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The lana-security v1.1.8 plugin demonstrates a generally strong security posture. Static analysis reveals no critical or high-severity issues in taint flows, and a very high percentage of output escaping, indicating good practices in preventing common web vulnerabilities like XSS. The plugin also implements a healthy number of nonce and capability checks, which are crucial for securing actions within WordPress. Furthermore, the absence of any recorded vulnerabilities, CVEs, or known common vulnerability types in its history suggests a history of secure development and maintenance.
However, a few areas warrant attention. The presence of SQL queries, with a significant portion not utilizing prepared statements (71% not prepared), presents a potential risk for SQL injection if these queries are not handled with extreme care or if external input directly influences their construction. While there are no external HTTP requests, the single file operation could be a vector for insecure file handling if not properly sanitized. The plugin's entry points are all protected, which is excellent, but the general reliance on prepared statements for all SQL queries should be a priority for a more robust security profile.
Key Concerns
- SQL queries not using prepared statements
Lana Security Security Vulnerabilities
Lana Security Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Lana Security Attack Surface
WordPress Hooks 33
Scheduled Events 4
Maintenance & Trust
Lana Security Maintenance & Trust
Maintenance Signals
Community Trust
Lana Security Alternatives
Wordfence Login Security
wordfence-login-security
Secure your website with Wordfence Login Security, providing two-factor authentication, login and registration CAPTCHA, and XML-RPC protection.
DoLogin Security
dologin
Easy Login. 2FA login. Passwordless login. Cloudflare Turnstile reCAPTCHA. GeoLocation (Continent/Country/City)/IP range to limit login attempts.
Cartpauj Register Captcha
cartpauj-register-captcha
Cartpauj Register Captcha does one simple task. It prevents SPAM signups through WordPress' default registration form.
Power Captcha reCAPTCHA
power-captcha-recaptcha
Protect WordPress/WooCommerce/Contact Form 7 forms from spam, brute-force attacks, fake comments, accounts, or registrations with Google reCAPTCHA.
Kaya Login Captcha
kaya-login-captcha
Adds a simple captcha on login form, register form and lost-password form.
Lana Security Developer Profile
13 plugins · 4K total installs
How We Detect Lana Security
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lana-security/assets/js/lana-security-settings-admin.js/wp-content/plugins/lana-security/assets/css/lana-security-settings-admin.css/wp-content/plugins/lana-security/assets/css/lana-security-login.css/wp-content/plugins/lana-security/assets/js/lana-security-settings-admin.jslana-security/assets/js/lana-security-settings-admin.js?ver=lana-security/assets/css/lana-security-settings-admin.css?ver=lana-security/assets/css/lana-security-login.css?ver=