
FS Login Devices Security & Risk Analysis
wordpress.org/plugins/login-devicesTrack and display all users devices used during authentication process
Is FS Login Devices Safe to Use in 2026?
Generally Safe
Score 85/100FS Login Devices has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "login-devices" plugin v1.0.1 exhibits a generally strong security posture based on the static analysis. It demonstrates good practices by utilizing prepared statements for nearly all SQL queries and properly escaping the vast majority of its output. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a reduced attack surface. Furthermore, the plugin has no recorded historical vulnerabilities, which is a very positive sign of its security development and maintenance.
However, there are significant concerns flagged by the taint analysis. Three out of four analyzed flows have unsanitized paths, with all of them being classified as high severity. While the static analysis indicates no "critical" severity issues, these high-severity unsanitized paths are a substantial risk. The plugin also has only one recorded nonce check and zero capability checks, leaving it vulnerable to potential Cross-Site Request Forgery (CSRF) attacks if its entry points were to be exploited, and indicating a lack of granular permission controls.
In conclusion, the "login-devices" plugin has a solid foundation in terms of common security practices like SQL sanitization and output escaping, and its clean vulnerability history is commendable. Nevertheless, the presence of multiple high-severity unsanitized paths and the limited use of nonce and capability checks represent critical security weaknesses that must be addressed to ensure the plugin's overall security.
Key Concerns
- High severity unsanitized taint flows found
- High severity unsanitized taint flows found
- High severity unsanitized taint flows found
- Missing capability checks
- Limited nonce checks
FS Login Devices Security Vulnerabilities
FS Login Devices Release Timeline
FS Login Devices Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
FS Login Devices Attack Surface
WordPress Hooks 7
Maintenance & Trust
FS Login Devices Maintenance & Trust
Maintenance Signals
Community Trust
FS Login Devices Alternatives
Edit Author Slug
edit-author-slug
Allows an admin (or capable user) to edit the author slug of a user, and change the author base.
Co-Authors Plus
co-authors-plus
Assign multiple bylines to posts, pages, and custom post types with a search-as-you-type input box.
Meks Smart Author Widget
meks-smart-author-widget
Easily display your author/user profile info inside WordPress widget.
Starbox – the Author Box for Humans
starbox
Starbox is the Author Box for Humans. Professional Themes to choose from, HTML5, Social Media Profiles, Google Authorship
Loggedin – Limit Concurrent Sessions
loggedin
Lightweight plugin that limits an account to a specific number of concurrent logins.
FS Login Devices Developer Profile
4 plugins · 110 total installs
How We Detect FS Login Devices
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/login-devices/assets/dist/js/admin.js/wp-content/plugins/login-devices/assets/dist/css/admin.css/wp-content/plugins/login-devices/assets/dist/js/admin.jslogin-devices/assets/dist/js/admin.js?ver=login-devices/assets/dist/css/admin.css?ver=HTML / DOM Fingerprints
js-delete-login-devicedata-action="fsld_delete_device"