
Check your Last Login Security & Risk Analysis
wordpress.org/plugins/last-login-on-dashboardThe ideal plugin to check your last login ip and time for his account security. Extra details like browser and operating system.
Is Check your Last Login Safe to Use in 2026?
Generally Safe
Score 92/100Check your Last Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "last-login-on-dashboard" plugin, version 1.1, presents a mixed security posture. On the positive side, there are no known CVEs, no dangerous functions are used, and all SQL queries are properly prepared. Furthermore, there are no external HTTP requests or file operations, which limits potential attack vectors. The absence of shortcodes, cron events, and REST API routes also contributes to a smaller attack surface. However, significant concerns arise from the static analysis. The most critical finding is the presence of a taint flow with an unsanitized path, indicating a potential vulnerability where user-supplied data could be misused. Compounding this, 100% of the output is unescaped, meaning that any dynamic data displayed by the plugin could be susceptible to Cross-Site Scripting (XSS) attacks. The lack of nonce and capability checks on any entry points, though the entry points are currently zero, is a proactive risk that could become exploitable if the plugin evolves to include them without proper security measures. The plugin's history shows no prior vulnerabilities, which is a positive sign, but it does not negate the present code-level risks. Overall, while the plugin demonstrates some good practices, the unescaped output and the unsanitized path taint flow represent immediate and actionable security risks that require attention.
Key Concerns
- Taint flow with unsanitized path detected
- All output unescaped
- No capability checks
- No nonce checks
Check your Last Login Security Vulnerabilities
Check your Last Login Release Timeline
Check your Last Login Code Analysis
Output Escaping
Data Flow Analysis
Check your Last Login Attack Surface
WordPress Hooks 2
Maintenance & Trust
Check your Last Login Maintenance & Trust
Maintenance Signals
Community Trust
Check your Last Login Alternatives
When Last Login
when-last-login
Show a users last login date by creating a sortable column in your WordPress users list.
Last Login Time
last-login-time
A lightweight plugin that allows you to see active users according to their last login time/date.
User Login Plus
user-login-plus
Show a users last login date by creating a sortable column in your WordPress users list.
Loggedin – Limit Concurrent Sessions
loggedin
Lightweight plugin that limits an account to a specific number of concurrent logins.
WPForce Logout – WordPress User Login Logout Management Plugin
wp-force-logout
Forcefully log out users from your WordPress site, manage online status, and track last login activity.
Check your Last Login Developer Profile
2 plugins · 10 total installs
How We Detect Check your Last Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
user-login-detail