Lana Single Sign On Security & Risk Analysis

wordpress.org/plugins/lana-sso

Creates the ability to login using Single Sign On via OAuth 2.0

20 active installs v1.2.0 PHP 5.6+ WP 4.0+ Updated Unknown
loginoauth-2-0oauth2single-sign-onsso
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Lana Single Sign On Safe to Use in 2026?

Generally Safe

Score 100/100

Lana Single Sign On has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

Based on the static analysis, "lana-sso" v1.2.0 appears to have a very strong security posture. The complete absence of unprotected entry points across AJAX, REST API, shortcodes, and cron events is commendable, indicating that the plugin is designed with security in mind, likely requiring authentication for all interactions. The code signals also reinforce this, showing a clean slate with no dangerous functions, proper SQL statement preparation, and 100% output escaping. The presence of nonce and capability checks further solidifies the security of the implemented functionalities. However, the plugin does make two external HTTP requests, which, while not inherently a vulnerability, represent a potential attack vector if the target endpoints are compromised or if the requests are not handled securely. The vulnerability history being completely clear is a very positive sign, suggesting a history of secure development and maintenance. Overall, the plugin demonstrates excellent security practices, with the external HTTP requests being the only minor point of consideration.

Key Concerns

  • External HTTP requests present
Vulnerabilities
None known

Lana Single Sign On Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Lana Single Sign On Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
36 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped36 total outputs
Attack Surface

Lana Single Sign On Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionlogin_enqueue_scriptslana-sso.php:32
actionadmin_enqueue_scriptslana-sso.php:47
actionadmin_enqueue_scriptslana-sso.php:73
actionadmin_initlana-sso.php:103
actionadmin_menulana-sso.php:106
actionadmin_post_lana_sso_delete_client_id_from_wpdblana-sso.php:302
actionadmin_post_lana_sso_delete_client_secret_from_wpdblana-sso.php:323
actionlogin_formlana-sso.php:344
filterrewrite_rules_arraylana-sso.php:361
filterquery_varslana-sso.php:373
actionparse_requestlana-sso.php:458
Maintenance & Trust

Lana Single Sign On Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedUnknown
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Lana Single Sign On Developer Profile

Lana Codes

13 plugins · 4K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
400 days
View full developer profile
Detection Fingerprints

How We Detect Lana Single Sign On

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lana-sso/assets/css/lana-sso-login.css/wp-content/plugins/lana-sso/assets/css/lana-sso-admin.css/wp-content/plugins/lana-sso/assets/libs/toastr/css/toastr.min.css/wp-content/plugins/lana-sso/assets/js/lana-sso-admin.js/wp-content/plugins/lana-sso/assets/libs/toastr/js/toastr.min.js
Script Paths
/wp-content/plugins/lana-sso/assets/js/lana-sso-admin.js
Version Parameters
lana-sso/assets/css/lana-sso-login.css?ver=lana-sso/assets/css/lana-sso-admin.css?ver=lana-sso/assets/js/lana-sso-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
lana-sso-admincopy-to-clipboardbutton-with-iconhide-if-no-jsconstant-client-idconstant-client-secretbutton-separator
Data Attributes
data-target
JS Globals
lana_sso_l10n
FAQ

Frequently Asked Questions about Lana Single Sign On