
Login as User Security & Risk Analysis
wordpress.org/plugins/login-as-userLogin as User is a free WordPress plugin that helps admins switch user accounts instantly to check data.
Is Login as User Safe to Use in 2026?
Generally Safe
Score 100/100Login as User has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "login-as-user" plugin v1.6.8 exhibits a generally strong security posture based on the static analysis. The absence of direct AJAX or REST API endpoints that bypass authentication is a significant positive. The code also demonstrates good practices by exclusively using prepared statements for SQL queries and incorporating both nonce and capability checks, indicating an awareness of common WordPress security vulnerabilities. The plugin also has no recorded vulnerability history, which is a strong indicator of stable and secure development over time.
However, there are minor areas for improvement. The taint analysis reveals one flow with unsanitized paths, which, while not classified as critical or high severity in this specific analysis, represents a potential avenue for unexpected behavior or vulnerabilities if input is not handled meticulously. Furthermore, the output escaping is only properly done in 72% of cases. While this might not lead to immediate critical issues, it leaves room for potential cross-site scripting (XSS) vulnerabilities if user-controlled data is rendered without proper sanitization in the remaining 28% of outputs.
Overall, the plugin is well-developed from a security perspective, with a minimal attack surface and a history free of known vulnerabilities. The primary concerns are the single unsanitized path flow and the imperfect output escaping, which are minor but should be addressed to achieve a truly robust security profile.
Key Concerns
- Flows with unsanitized paths
- Output escaping not fully proper
Login as User Security Vulnerabilities
Login as User Code Analysis
Output Escaping
Data Flow Analysis
Login as User Attack Surface
Shortcodes 1
WordPress Hooks 63
Maintenance & Trust
Login as User Maintenance & Trust
Maintenance Signals
Community Trust
Login as User Alternatives
Masquerade
masquerade
Adds a link to users.php that allows an administrator to login as that user without knowing the password.
WP Last Login
wp-last-login
Make the last login for each user visible in the user overview.
WP Approve User
wp-approve-user
Adds action links to user table to approve or unapprove user registrations.
User Login Notifier for WordPress
wp-user-login-notifier
User Login Notifier plugin notifies WordPress site admin and users of the successful and failed login attempts via email.
Chap Secure Password Login
chap-secure-login
Do not show password, during login, on an insecure channel (without SSL). Use a SHA-256 hash algorithm.
Login as User Developer Profile
4 plugins · 30K total installs
How We Detect Login as User
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/login-as-user/admin/css/admin.min.css/wp-content/plugins/login-as-user/admin/js/admin.min.js/wp-content/plugins/login-as-user/admin/js/admin.min.jslogin-as-user/admin/css/admin.min.css?ver=login-as-user/admin/js/admin.min.js?ver=HTML / DOM Fingerprints
column-loginasuser_col Login as User for WordPress - v1.6.8 (free version) Author: Web357 Copyright © 2014-2024 Web357. All rights reserved. License: GNU/GPLv3, http://www.gnu.org/licenses/gpl-3.0.html +4 moredata-loginasuser_idloginasuserAjax