
Login Links – Passwordless Login, Temporary Access Links & Custom Login Form Security & Risk Analysis
wordpress.org/plugins/login-linksCreate secure self-expiring login links for temporary access and guest users, and enable passwordless login for registered ones.
Is Login Links – Passwordless Login, Temporary Access Links & Custom Login Form Safe to Use in 2026?
Generally Safe
Score 100/100Login Links – Passwordless Login, Temporary Access Links & Custom Login Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "login-links" v2.1.0 plugin exhibits a generally good security posture, with several positive indicators. The absence of dangerous functions, the use of prepared statements for all SQL queries, and a high percentage of properly escaped output are commendable practices. Furthermore, the plugin has no recorded vulnerabilities or CVEs, suggesting a history of stable and secure development.
However, there is a specific area of concern related to the REST API. One out of seven REST API routes lacks permission callbacks, creating a potential entry point that is not properly secured. While the static analysis and taint analysis did not reveal any critical or high-severity issues, this single unprotected REST API route represents a tangible risk that could be exploited if not addressed. The presence of nonce and capability checks is positive, but their limited number (two each) might indicate that not all sensitive operations are adequately protected.
In conclusion, "login-links" v2.1.0 is largely secure, benefiting from good coding practices in most areas. The primary weakness lies in the unprotected REST API route, which should be prioritized for remediation. The lack of historical vulnerabilities is a strong positive, but it does not negate the need to address the identified security gap in the current version.
Key Concerns
- Unprotected REST API route
Login Links – Passwordless Login, Temporary Access Links & Custom Login Form Security Vulnerabilities
Login Links – Passwordless Login, Temporary Access Links & Custom Login Form Code Analysis
SQL Query Safety
Output Escaping
Login Links – Passwordless Login, Temporary Access Links & Custom Login Form Attack Surface
REST API Routes 7
Shortcodes 1
WordPress Hooks 26
Maintenance & Trust
Login Links – Passwordless Login, Temporary Access Links & Custom Login Form Maintenance & Trust
Maintenance Signals
Community Trust
Login Links – Passwordless Login, Temporary Access Links & Custom Login Form Alternatives
Temporary Login Without Password
temporary-login-without-password
Create self-expiring, temporary admin accounts. Easily share direct login links (no need for username/password) with your developers or editors.
SafeTemp Login – Temporary Access with Approval
safetemplogin-tawa
Create temporary users with any role. When a temporary user is an administrator, sensitive actions require approval from a real administrator.
Temporary Login
temporary-login
Create a secure, temporary URL for easy access to your WP admin.
Passwordless Login
passwordless-login
Passwordless login form via a simple to use shortcode: [passwordless-login]
Bifröst – Instant Passwordless Temporary Login Links
create-temporary-login
🔗️ Create passwordless temporary login links. Instantly ⚡️
Login Links – Passwordless Login, Temporary Access Links & Custom Login Form Developer Profile
2 plugins · 1K total installs
How We Detect Login Links – Passwordless Login, Temporary Access Links & Custom Login Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.