
Last Login Info Display Security & Risk Analysis
wordpress.org/plugins/last-login-info-displayTrack user activity with a detailed "Last Login" and "Login Count" column in the WordPress Users dashboard.
Is Last Login Info Display Safe to Use in 2026?
Generally Safe
Score 100/100Last Login Info Display has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "last-login-info-display" v1.1.1 exhibits a generally good security posture with several strengths. Notably, it avoids dangerous functions, performs all SQL queries using prepared statements, and has a good rate of output escaping (81%). The absence of file operations and external HTTP requests further reduces potential attack vectors. Its vulnerability history is clean, with no recorded CVEs, indicating a potentially well-maintained and secure codebase.
However, a significant concern arises from the static analysis, which identified one AJAX handler that lacks authentication checks. This unprotected entry point represents a direct risk, as it could be exploited by unauthenticated users to trigger potentially unintended actions or reveal sensitive information. While taint analysis shows no critical or high-severity issues, and only a limited attack surface, this single unprotected AJAX handler is a clear vulnerability that needs immediate attention. The presence of a nonce check is positive, but its absence on this specific handler negates its protective effect for that entry point.
In conclusion, the plugin demonstrates solid coding practices in many areas, particularly regarding data handling and output sanitation. The clean vulnerability history is a strong positive signal. Nevertheless, the unprotected AJAX handler is a critical weakness that significantly lowers its overall security score and requires remediation.
Key Concerns
- Unprotected AJAX handler without auth checks
Last Login Info Display Security Vulnerabilities
Last Login Info Display Code Analysis
Output Escaping
Last Login Info Display Attack Surface
AJAX Handlers 3
WordPress Hooks 25
Maintenance & Trust
Last Login Info Display Maintenance & Trust
Maintenance Signals
Community Trust
Last Login Info Display Alternatives
CodeCave Admin Security Auditor
codecave-admin-security-auditor
Track and display the last login time for each user in the WordPress admin users table.
Last Login Info
last-login-info
Displays the last login timestamp of each user in the WordPress admin Users table, with tools to export and manage login data.
Login Defender
login-defender
Login Defender enhances your WordPress site's security by allowing you to change the default login URL.
Storm Clean Admin
storm-clean-admin
A modern WordPress plugin to manage inactive users, monitor site activity, and keep your site optimized and secure.
Loginizer
loginizer
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Last Login Info Display Developer Profile
1 plugin · 0 total installs
How We Detect Last Login Info Display
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/last-login-info-display/admin/css/llid-admin.css/wp-content/plugins/last-login-info-display/admin/js/llid-admin.js/wp-content/plugins/last-login-info-display/admin/js/llid-admin.jslast-login-info-display/admin/css/llid-admin.css?ver=last-login-info-display/admin/js/llid-admin.js?ver=HTML / DOM Fingerprints
column-last-logincolumn-login-count<!-- BEGIN: last-login-info-display --><!-- END: last-login-info-display --><!-- BEGIN: LLID Settings --><!-- END: LLID Settings -->+1 moredata-llid-user-id