
LNURL Auth For WordPress Security & Risk Analysis
wordpress.org/plugins/lnurl-authThis plugin provides LNURL Auth for WordPress. Login to WordPress with Bitcoin Lightning ⚡️
Is LNURL Auth For WordPress Safe to Use in 2026?
Generally Safe
Score 92/100LNURL Auth For WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lnurl-auth" v1.0.14 plugin presents a mixed security posture. On the positive side, it demonstrates good practices regarding database interactions, with 100% of SQL queries utilizing prepared statements and no file operations or external HTTP requests detected. The plugin also exhibits strong output sanitization, with 90% of its outputs being properly escaped. Furthermore, the absence of any recorded vulnerabilities in its history suggests a generally stable and well-maintained codebase.
However, significant concerns arise from the plugin's attack surface. Out of five total entry points, four are unprotected AJAX handlers. This lack of authentication checks on a substantial portion of its exposed functionality is a critical security weakness. While no direct taint flows were identified in the static analysis, the presence of unprotected AJAX endpoints significantly increases the risk of various injection attacks if any user-supplied data is processed without proper validation and sanitization within these handlers.
In conclusion, while the "lnurl-auth" plugin benefits from secure database handling and good output escaping, the unprotected AJAX handlers represent a substantial risk. The absence of known vulnerabilities is encouraging, but this should not overshadow the immediate security implications of a large, unauthenticated attack surface. Addressing these unprotected entry points should be a top priority to improve the plugin's overall security.
Key Concerns
- 4 unprotected AJAX handlers
- 0 Nonce checks
- 1 Dangerous function (ini_set)
LNURL Auth For WordPress Security Vulnerabilities
LNURL Auth For WordPress Release Timeline
LNURL Auth For WordPress Code Analysis
Dangerous Functions Found
Output Escaping
LNURL Auth For WordPress Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
LNURL Auth For WordPress Maintenance & Trust
Maintenance Signals
Community Trust
LNURL Auth For WordPress Alternatives
YEGHRO Nostr Login
nostr-login
Enable secure WordPress authentication using Nostr keys - login with your Nostr identity.
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Limit Login Attempts
limit-login-attempts
Limit rate of login attempts, including by way of cookies, for each IP. Fully customizable.
WPS Limit Login
wps-limit-login
WPS Limit login limit connection attempts by IP address
Wordfence Login Security
wordfence-login-security
Secure your website with Wordfence Login Security, providing two-factor authentication, login and registration CAPTCHA, and XML-RPC protection.
LNURL Auth For WordPress Developer Profile
4 plugins · 350 total installs
How We Detect LNURL Auth For WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lnurl-auth/assets/css/lnurl-auth.css/wp-content/plugins/lnurl-auth/assets/css/lnurl-auth-admin.css/wp-content/plugins/lnurl-auth/assets/js/lnurl-auth.js/wp-content/plugins/lnurl-auth/assets/js/lnurl-auth.jslnurl-auth/assets/css/lnurl-auth.css?ver=lnurl-auth/assets/css/lnurl-auth-admin.css?ver=lnurl-auth/assets/js/lnurl-auth.js?ver=HTML / DOM Fingerprints
lnurl-authlnurl-auth-qrcodelnurl-auth-permalinklnurl-auth-timer-clocklnurl-auth-timer-minuteslnurl-auth-timer-secondslnurl-auth-messagedata-foregrounddata-backgroundlnurlAuthElementClassintersectionObserver/wp-json/lnurl-auth/v1/lnurl-auth