Lana Single Sign On Security & Risk Analysis

wordpress.org/plugins/lana-sso

Creates the ability to login using Single Sign On via OAuth 2.0

10 active installs v1.2.0 PHP 5.6+ WP 4.0+ Updated Oct 20, 2024
loginoauth-2-0oauth2single-sign-onsso
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Lana Single Sign On Safe to Use in 2026?

Generally Safe

Score 92/100

Lana Single Sign On has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

Based on the static analysis, "lana-sso" v1.2.0 appears to have a very strong security posture. The complete absence of unprotected entry points across AJAX, REST API, shortcodes, and cron events is commendable, indicating that the plugin is designed with security in mind, likely requiring authentication for all interactions. The code signals also reinforce this, showing a clean slate with no dangerous functions, proper SQL statement preparation, and 100% output escaping. The presence of nonce and capability checks further solidifies the security of the implemented functionalities. However, the plugin does make two external HTTP requests, which, while not inherently a vulnerability, represent a potential attack vector if the target endpoints are compromised or if the requests are not handled securely. The vulnerability history being completely clear is a very positive sign, suggesting a history of secure development and maintenance. Overall, the plugin demonstrates excellent security practices, with the external HTTP requests being the only minor point of consideration.

Key Concerns

  • External HTTP requests present
Vulnerabilities
None known

Lana Single Sign On Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Lana Single Sign On Release Timeline

v1.2.0Current
v1.1.0
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Lana Single Sign On Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
36 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped36 total outputs
Attack Surface

Lana Single Sign On Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionlogin_enqueue_scriptslana-sso.php:32
actionadmin_enqueue_scriptslana-sso.php:47
actionadmin_enqueue_scriptslana-sso.php:73
actionadmin_initlana-sso.php:103
actionadmin_menulana-sso.php:106
actionadmin_post_lana_sso_delete_client_id_from_wpdblana-sso.php:302
actionadmin_post_lana_sso_delete_client_secret_from_wpdblana-sso.php:323
actionlogin_formlana-sso.php:344
filterrewrite_rules_arraylana-sso.php:361
filterquery_varslana-sso.php:373
actionparse_requestlana-sso.php:458
Maintenance & Trust

Lana Single Sign On Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 20, 2024
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Lana Single Sign On Developer Profile

Lana Codes

15 plugins · 4K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
349 days
View full developer profile
Detection Fingerprints

How We Detect Lana Single Sign On

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lana-sso/assets/css/lana-sso-login.css/wp-content/plugins/lana-sso/assets/css/lana-sso-admin.css/wp-content/plugins/lana-sso/assets/libs/toastr/css/toastr.min.css/wp-content/plugins/lana-sso/assets/js/lana-sso-admin.js/wp-content/plugins/lana-sso/assets/libs/toastr/js/toastr.min.js
Script Paths
/wp-content/plugins/lana-sso/assets/js/lana-sso-admin.js
Version Parameters
lana-sso/assets/css/lana-sso-login.css?ver=lana-sso/assets/css/lana-sso-admin.css?ver=lana-sso/assets/js/lana-sso-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
lana-sso-admincopy-to-clipboardbutton-with-iconhide-if-no-jsconstant-client-idconstant-client-secretbutton-separator
Data Attributes
data-target
JS Globals
lana_sso_l10n
FAQ

Frequently Asked Questions about Lana Single Sign On