
Last Login Time Security & Risk Analysis
wordpress.org/plugins/last-login-timeA lightweight plugin that allows you to see active users according to their last login time/date.
Is Last Login Time Safe to Use in 2026?
Generally Safe
Score 85/100Last Login Time has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "last-login-time" v1.0.0 plugin exhibits a strong initial security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code analysis reveals a clean bill of health, with no dangerous functions, file operations, or external HTTP requests. All SQL queries, though few, are prepared, and output is properly escaped, indicating good development practices in these areas.
Taint analysis shows no identified flows with unsanitized paths, which is a positive sign for preventing common injection vulnerabilities. The vulnerability history is also completely clean, with no recorded CVEs, suggesting a lack of known security flaws. The plugin's strengths lie in its limited functionality and adherence to secure coding principles in the analyzed aspects.
However, the analysis also highlights potential areas of concern due to the *absence* of certain security checks. The complete lack of nonces and capability checks across all potential entry points, even though there are currently zero, suggests a potential weakness if any entry points were to be added or exposed in future updates without proper security considerations. This indicates a lack of built-in authorization and validation mechanisms that are crucial for preventing unauthorized actions. While the current version appears safe due to its limited exposure, future development should incorporate these essential security checks.
Key Concerns
- No nonce checks found
- No capability checks found
Last Login Time Security Vulnerabilities
Last Login Time Release Timeline
Last Login Time Code Analysis
Last Login Time Attack Surface
WordPress Hooks 10
Maintenance & Trust
Last Login Time Maintenance & Trust
Maintenance Signals
Community Trust
Last Login Time Alternatives
When Last Login
when-last-login
Show a users last login date by creating a sortable column in your WordPress users list.
User Login Plus
user-login-plus
Show a users last login date by creating a sortable column in your WordPress users list.
Check your Last Login
last-login-on-dashboard
The ideal plugin to check your last login ip and time for his account security. Extra details like browser and operating system.
WPForce Logout – WordPress User Login Logout Management Plugin
wp-force-logout
Forcefully log out users from your WordPress site, manage online status, and track last login activity.
When Last Login – Export User Records
when-last-login-export-user-records
Export your user's login records into a CSV or JSON file in seconds.
Last Login Time Developer Profile
5 plugins · 40 total installs
How We Detect Last Login Time
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/last-login-time/css/sg-last-login-time-admin.css/wp-content/plugins/last-login-time/js/sg-last-login-time-admin.js/wp-content/plugins/last-login-time/js/sg-last-login-time-admin.jssg-last-login-timelast-login-time