
Login Gatekeeper Security & Risk Analysis
wordpress.org/plugins/login-gatekeeperProtect your login page by requiring a secret key and value in the login URL.
Is Login Gatekeeper Safe to Use in 2026?
Generally Safe
Score 100/100Login Gatekeeper has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'login-gatekeeper' v1.0.0 plugin exhibits a strong initial security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code analysis reveals no dangerous functions, file operations, or external HTTP requests. All SQL queries are properly prepared, and all output is correctly escaped. The lack of any recorded historical vulnerabilities further reinforces this positive assessment, suggesting a consistent focus on secure development practices.
However, a notable concern arises from the complete absence of nonce checks and capability checks. While the current attack surface is zero, this lack of fundamental security controls means that if any new entry points are introduced in future versions, they would be inherently vulnerable to CSRF and unauthorized access. The taint analysis showing zero flows, while positive, could be a result of the minimal attack surface, and does not necessarily guarantee future safety if code changes. Therefore, while 'login-gatekeeper' appears secure in its current state, the omission of basic security mechanisms represents a significant future risk.
In conclusion, 'login-gatekeeper' v1.0.0 is currently very secure due to a minimal attack surface and diligent coding practices regarding SQL and output escaping. The absence of historical vulnerabilities is a strong positive indicator. The primary weakness lies in the complete lack of nonce and capability checks, which, while not exploitable in the current version, poses a substantial risk for future maintainability and security. This plugin is recommended for use in its current version, but with a strong caveat regarding the need for implementing these security measures in any future updates.
Key Concerns
- Missing nonce checks
- Missing capability checks
Login Gatekeeper Security Vulnerabilities
Login Gatekeeper Release Timeline
Login Gatekeeper Code Analysis
Output Escaping
Login Gatekeeper Attack Surface
WordPress Hooks 6
Maintenance & Trust
Login Gatekeeper Maintenance & Trust
Maintenance Signals
Community Trust
Login Gatekeeper Alternatives
Security Hardener
security-hardener
Basic hardening: secure headers, login honeypot, user enumeration blocking, generic login errors, rate limiting, and more.
Anti-Brute Force, Login Fraud Detector WordPress plugin
anti-brute-force-login-fraud-detector
Anti-Brute Force, Login Fraud Detector Wordpress plugin is a security plugin that detects and blocks malicious IP addresses attempting to log into Wor …
Cyber Smart Defence
cyber-smart-defence
Lightweight WordPress security firewall with login protection and threat monitoring.
Gatorio
gatorio
Lightweight brute-force protection for the WordPress login.
Luckduo Login Guard
luckduo-login-guard
Short Description: Protect your WordPress login from brute-force attacks with IP lock and login attempt limits.
Login Gatekeeper Developer Profile
9 plugins · 31K total installs
How We Detect Login Gatekeeper
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/login-gatekeeper/assets/css/login-gatekeeper.csslogin-gatekeeper/assets/css/login-gatekeeper.css?ver=login-gatekeeper/assets/js/login-gatekeeper.js?ver=