
Active Directory Integration / LDAP Integration Security & Risk Analysis
wordpress.org/plugins/ldap-login-for-intranet-sitesActive Directory Integration/LDAP Integration enables login & sync in WordPress with Active Directory/LDAP Directory credentials, 24/7 ACTIVE SUPPORT
Is Active Directory Integration / LDAP Integration Safe to Use in 2026?
Generally Safe
Score 97/100Active Directory Integration / LDAP Integration has a strong security track record. Known vulnerabilities have been patched promptly.
The "ldap-login-for-intranet-sites" plugin v5.4.0 exhibits a mixed security posture. On the positive side, the static analysis reveals an absence of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events that are unprotected. Furthermore, all output appears to be properly escaped, and there are no file operations or bundled libraries to scrutinize. However, concerns arise from the vulnerability history, which includes 7 known CVEs, with 6 still considered high or medium severity. Common vulnerability types found in the past, such as LDAP Injection, SQL Injection, and Cross-Site Request Forgery, are particularly worrying for a plugin handling authentication.
The taint analysis shows a concerning number of flows with unsanitized paths, even though they are not currently categorized as critical or high severity. This suggests potential areas where user-supplied data might not be sufficiently validated before being used in sensitive operations. The presence of external HTTP requests also introduces a potential attack vector if these endpoints are not secured or are vulnerable themselves. While the plugin demonstrates good practices in output escaping and lack of immediate attack surface, the historical prevalence of severe vulnerabilities and the identified unsanitized flows necessitate caution.
Key Concerns
- History of 7 known CVEs, 6 still high/medium
- 4 flows with unsanitized paths
- 7 external HTTP requests
- 40% of SQL queries not using prepared statements
Active Directory Integration / LDAP Integration Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
Active Directory Integration / LDAP Integration <= 4.1.9 - Sensitive Information Exposure
Active Directory Integration / LDAP Integration <= 4.1.9 - Unauthenticated Information Disclosure
Active Directory Integration / LDAP Integration <= 4.1.5 - Authenticated (Subscriber+) LDAP Injection
Active Directory Integration / LDAP Integration <= 4.1.4 - Authenticated (Administrator+) SQL Injection
Active Directory Integration / LDAP Integration <= 4.1.4 - Cross-Site Request Forgery to SQL Injection
Active Directory Integration / LDAP Integration <= 4.1.0 - Unauthenticated Information Disclosure
Active Directory Integration / LDAP Integration <= 3.6.94 - Reflected Cross-Site Scripting
Active Directory Integration / LDAP Integration Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Active Directory Integration / LDAP Integration Attack Surface
WordPress Hooks 11
Maintenance & Trust
Active Directory Integration / LDAP Integration Maintenance & Trust
Maintenance Signals
Community Trust
Active Directory Integration / LDAP Integration Alternatives
Active Directory/LDAP Integration for Cloud & Shared Hosting Platforms
miniorange-wp-ldap-login
Active Directory integration/LDAP integration enables authentication & login for WordPress sites on Shared Hosting like Bluehost, GoDaddy, SiteGro …
authLdap
authldap
Use your existing LDAP flexible as authentication backend for WordPress
Next Active Directory Integration
next-active-directory-integration
Next Active Directory Integration allows WordPress to authenticate, authorize, create and update users against Microsoft Active Directory.
Simple LDAP Login
simple-ldap-login
Integrating WordPress with LDAP shouldn't be difficult. Now it isn't. Simple LDAP Login provides all of the features, none of the hassles.
Active Directory Authentication Integration
active-directory-authentication-integration
Allows WordPress to authenticate, authorize, create and update users through Active Directory
Active Directory Integration / LDAP Integration Developer Profile
38 plugins · 83K total installs
How We Detect Active Directory Integration / LDAP Integration
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ldap-login-for-intranet-sites/resources/css/admin.css/wp-content/plugins/ldap-login-for-intranet-sites/resources/css/login.css/wp-content/plugins/ldap-login-for-intranet-sites/resources/js/admin.js/wp-content/plugins/ldap-login-for-intranet-sites/resources/js/login.js/wp-content/plugins/ldap-login-for-intranet-sites/resources/js/admin.js/wp-content/plugins/ldap-login-for-intranet-sites/resources/js/login.jsldap-login-for-intranet-sites/resources/css/admin.css?ver=ldap-login-for-intranet-sites/resources/css/login.css?ver=ldap-login-for-intranet-sites/resources/js/admin.js?ver=ldap-login-for-intranet-sites/resources/js/login.js?ver=HTML / DOM Fingerprints
mo-ldap-local-loginmo-ldap-local-admin<!-- MiniOrange LDAP Login Configuration --><!-- MiniOrange LDAP Login Status --><!-- MiniOrange LDAP Login Feedback -->data-mo-ldap-login-settingsdata-mo-ldap-login-statusMoLdapLoginAdminMoLdapLogin