
Logged in Security & Risk Analysis
wordpress.org/plugins/logged-inAllows you to close your site to non-logged in users, by redirecting them to the login page, displaying a message or a specific template file.
Is Logged in Safe to Use in 2026?
Generally Safe
Score 85/100Logged in has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "logged-in" plugin v1.0.4 exhibits a generally strong security posture based on the static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code shows good practices by not utilizing dangerous functions, performing file operations, making external HTTP requests, or bundling libraries that could introduce vulnerabilities. All SQL queries are handled with prepared statements, which is excellent for preventing SQL injection.
However, a critical concern arises from the output escaping. With 100% of identified outputs not being properly escaped, this plugin presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic content rendered by this plugin could be exploited to inject malicious scripts into users' browsers. While the vulnerability history is clean, indicating a lack of past issues, this does not negate the immediate risk posed by the unescaped output.
In conclusion, the plugin demonstrates a robust foundation in preventing many common web vulnerabilities by limiting its entry points and securing its data interactions. The lack of historical vulnerabilities is positive. Nevertheless, the failure to escape output is a major oversight that could lead to severe security breaches, specifically XSS attacks. Addressing the output escaping is paramount to improving the plugin's overall security.
Key Concerns
- Output not properly escaped
Logged in Security Vulnerabilities
Logged in Code Analysis
Output Escaping
Logged in Attack Surface
WordPress Hooks 4
Maintenance & Trust
Logged in Maintenance & Trust
Maintenance Signals
Community Trust
Logged in Alternatives
Login External Redirect
login-external-redirect
This plugin can redirect non users or not signed in users to any external or internal url.
LoginWP (Formerly Peter's Login Redirect)
peters-login-redirect
Redirect users to different locations after they log in, log out and register based on different conditions.
When Last Login
when-last-login
Show a users last login date by creating a sortable column in your WordPress users list.
Inactive Logout
inactive-logout
Automatically logout idle user sessions, with logout redirections and concurrent limit logins all in one place.
FluentAuth – The Ultimate Authorization & Security Plugin for WordPress
fluent-security
Enhance the Security and User Experience of Your Site with Login/Signup Security, Two-Factor Email Authentication, Social Logins and more...
Logged in Developer Profile
2 plugins · 20 total installs
How We Detect Logged in
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/logged-in/js/admin.js/wp-content/plugins/logged-in/js/admin.js