
Login as User or Customer Security & Risk Analysis
wordpress.org/plugins/login-as-customer-or-userThis plugin allows you to quickly swap between user accounts in WordPress (in one click). This is very helpful for admins or customer support users to …
Is Login as User or Customer Safe to Use in 2026?
Mostly Safe
Score 70/100Login as User or Customer is generally safe to use. 5 past CVEs were resolved.
The "login-as-customer-or-user" v3.9.1 plugin presents a mixed security posture. While the static analysis indicates a relatively small attack surface with no unprotected entry points and a strong adherence to prepared statements for SQL queries, the plugin's history is a significant concern. The presence of 5 known CVEs, with 2 critically severe and unpatched vulnerabilities, suggests a pattern of recurring security flaws. These historical issues, including authentication bypass, improper authentication/authorization, and CSRF, highlight potential weaknesses in how the plugin handles user access and session management. Despite the current static analysis showing no critical taint flows and good output escaping, the past vulnerability record indicates that these aspects may have been compromised in previous versions, and the current version might still harbor latent risks or be susceptible to similar attack vectors.
Key Concerns
- Unpatched Critical Vulnerabilities
- Significant Vulnerability History (5 CVEs)
- High rate of Critical/High severity CVEs
- Potential for previously exploited vulnerabilities
Login as User or Customer Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Login as User or Customer <= 3.8 - Unauthenticated Limited Admin Account Compromise
Login as User or Customer (User Switching) <= 3.8 - Authentication Bypass
Login as User or Customer <= 3.2 - Privilege Escalation
Login as User or Customer <= 2.1 - Cross-Site Request Forgery to Arbitrary Plugin Installation/Activation
Login as User or Customer < 1.8 - Missing Authorization to Arbitrary Plugin Installation/Activation
Login as User or Customer Release Timeline
Login as User or Customer Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Login as User or Customer Attack Surface
AJAX Handlers 2
WordPress Hooks 19
Maintenance & Trust
Login as User or Customer Maintenance & Trust
Maintenance Signals
Community Trust
Login as User or Customer Alternatives
Passe-partout, login as a different user
passe-partout
The main administrators with their own password will be able to log in with whatever registered user account.
Force Login by Webline
force-user-login-by-webline
This plugin provides a feature to make your site restricted and user is required to login to view protected pages.
dpabadbotwp
dpabadbotwp
This plugin, dpaBadBotWP, automatically tells Bad Bot Exterminator firewall software, your current IP address and you will not be blocked from working …
Prevent Brute Force Login
ervan-limit-login
Limit the number of login attempts by ip address.
Login Mandatory Pages
login-mandatory-pages
Login Mandatory pages is a WordPress plugin that allows you to make pages accessible for only logged in users.
Login as User or Customer Developer Profile
15 plugins · 345K total installs
How We Detect Login as User or Customer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/login-as-customer-or-user/assets/css/loginas.css/wp-content/plugins/login-as-customer-or-user/assets/js/loginas.js/wp-content/plugins/login-as-customer-or-user/assets/js/loginas.jslogin-as-customer-or-user/assets/css/loginas.css?ver=login-as-customer-or-user/assets/js/loginas.js?ver=HTML / DOM Fingerprints
loginas_buttondata-loginas-user-idloginas_vars