
Login-Logout Security & Risk Analysis
wordpress.org/plugins/login-logoutWidget with login, logout, admin and register links. Replacement of the default Meta widget.
Is Login-Logout Safe to Use in 2026?
Use With Caution
Score 63/100Login-Logout has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The login-logout plugin version 3.8 presents a mixed security posture. On the positive side, it demonstrates good practices by having no known dangerous functions, performing all SQL queries using prepared statements, and avoiding file operations and external HTTP requests. Furthermore, the attack surface appears to be minimal, with no identified AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, no unprotected entry points. However, several areas raise significant concerns. The output escaping is notably poor, with only 27% of outputs being properly escaped, suggesting a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis, though limited in scope, revealed two flows with unsanitized paths, which, while not currently categorized as critical or high, warrants attention. The plugin's vulnerability history is a significant red flag, with one unpatched medium severity CVE for XSS. The fact that this is the most recent vulnerability and it remains unpatched indicates a potential lack of ongoing security maintenance and a recurring pattern of XSS issues.
Key Concerns
- Unpatched medium CVE (XSS)
- Low output escaping (27%)
- Taint flows with unsanitized paths
- No nonce checks
- No capability checks
Login-Logout Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Login-Logout <= 3.8 - Authenticated (Administrator+) Stored Cross-Site Scripting
Login-Logout Release Timeline
Login-Logout Code Analysis
Output Escaping
Data Flow Analysis
Login-Logout Attack Surface
WordPress Hooks 3
Maintenance & Trust
Login-Logout Maintenance & Trust
Maintenance Signals
Community Trust
Login-Logout Alternatives
Sidebar Login Widget
tt-sidebar-login-widget
I Appreciate if you please give reviews and any suggestions after using this plugin. If you like this plugin you can donate or contribute by clicking …
Sidebar Login
sidebar-login
Easily add an ajax-enhanced login widget to your WordPress site sidebar.
Login Widget With Shortcode
login-sidebar-widget
This is a simple login form in the widget. This will allow users to login to the site from frontend.
bbPress Login Register Links On Forum Topic Pages
bbpress-login-register-links-on-forum-topic-pages
Add bbPress only sidebar, Add bbpress login link, bbpress register link, forget password link, log out link in bbpress forum index pages or bbpress si …
Login-Logout
login-and-out
Adds simple, clean links so users can login/logout & register easily. Highly customisable, & can be used as a widget or inserted into your sit …
Login-Logout Developer Profile
14 plugins · 128K total installs
How We Detect Login-Logout
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
widget_login_logoutwrap_login_logoutitem_welcomeitem_loginitem_logoutitem_registeritem_adminitem_extra_login+1 more<!-- Powered by Login-Logout plugin v.3.8 wordpress.org/plugins/login-logout/ -->