
Logged In As Security & Risk Analysis
wordpress.org/plugins/logged-in-asShow the currently logged in user name and avatar
Is Logged In As Safe to Use in 2026?
Generally Safe
Score 100/100Logged In As has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'logged-in-as' plugin v1.1.1 exhibits a generally positive security posture based on the static analysis provided. The absence of any identified CVEs in its history and the lack of dangerous functions, file operations, external HTTP requests, and SQL queries (all using prepared statements) are strong indicators of secure coding practices. Furthermore, the plugin demonstrates a very limited attack surface with no identifiable entry points such as AJAX handlers, REST API routes, or shortcodes that lack authentication or permission checks.
However, a significant concern arises from the output escaping. With only 25% of outputs being properly escaped, this leaves a considerable portion vulnerable to potential cross-site scripting (XSS) attacks. While the taint analysis shows no explicit unsanitized flows, the lack of consistent output escaping is a weakness that could be exploited if data processed by the plugin is later rendered without proper sanitization elsewhere.
In conclusion, while the plugin is strong in preventing many common web vulnerabilities by design and has a clean vulnerability history, the poor output escaping is a notable weakness. This could potentially lead to XSS vulnerabilities, especially if user-supplied data is involved in the plugin's operations, even if not directly handled by the plugin's own entry points.
Key Concerns
- Poor output escaping (only 25% proper)
Logged In As Security Vulnerabilities
Logged In As Code Analysis
Output Escaping
Logged In As Attack Surface
WordPress Hooks 8
Maintenance & Trust
Logged In As Maintenance & Trust
Maintenance Signals
Community Trust
Logged In As Alternatives
ExpressTechSoftwares Addon for MemberPress and Discord
expresstechsoftwares-memberpress-discord-add-on
This add-on enables connecting your MemberPress enabled website to your discord server. Now you can add/remove MemberPress members directly to your di …
WPJ Reports for MemberPress
pro-reports-for-memberpress
Show MemberPress reports with more detail. More sales information, date-ranges, and filtering options.
myCred – MemberPress Integration (Gamification for Membership Sites)
mycred-memberpress
Take your MemberPress process to the next level with myCred MemberPress add-on - The best WordPress gamification add-on for MemberPress.
Dashboard Search for MemberPress
dashboard-search-memberpress
Search for MemberPress members right from your WordPress Dashboard. Saves you a few clicks.
BadgeOS MemberPress Integration
badgeos-memberpress-integration
MemberPress
Logged In As Developer Profile
3 plugins · 250 total installs
How We Detect Logged In As
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
logged-in-as/style.css?ver=logged-in-as_styleHTML / DOM Fingerprints
liam-icon