
Login Logout Menu Security & Risk Analysis
wordpress.org/plugins/login-logout-menuLogin Logout Menu is a handy plugin which allows you to add login, logout, register and profile menu items in your selected menu.
Is Login Logout Menu Safe to Use in 2026?
Generally Safe
Score 100/100Login Logout Menu has a strong security track record. Known vulnerabilities have been patched promptly.
The 'login-logout-menu' plugin version 1.5.2 exhibits a generally good security posture based on the provided static analysis. It successfully utilizes prepared statements for its SQL queries and boasts an exceptionally high rate of properly escaped output, minimizing common Cross-Site Scripting (XSS) risks. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security profile. Furthermore, the plugin has no currently unpatched vulnerabilities, indicating active maintenance in addressing past security issues.
However, a notable concern arises from the complete lack of nonce and capability checks across all identified entry points. While the static analysis did not reveal any directly exploitable unsanitized taint flows or unprotected AJAX/REST API endpoints, this absence of authorization checks means that any of the 7 shortcodes, if designed to perform sensitive actions or display user-specific data, could potentially be manipulated by unauthenticated users. The plugin's history of a medium severity XSS vulnerability, even though patched, serves as a reminder that such vulnerabilities can exist and require diligent implementation of authorization and input validation mechanisms.
In conclusion, the plugin demonstrates strong technical coding practices for preventing many common vulnerabilities. The primary weakness lies in the lack of comprehensive authorization checks, which, while not leading to direct critical findings in this analysis, represents a potential risk that should be addressed to ensure robust security.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- One medium severity CVE in history
- High percentage of unescaped output
Login Logout Menu Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Login Logout Menu <= 1.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Login Logout Menu Code Analysis
Output Escaping
Login Logout Menu Attack Surface
Shortcodes 7
WordPress Hooks 5
Maintenance & Trust
Login Logout Menu Maintenance & Trust
Maintenance Signals
Community Trust
Login Logout Menu Alternatives
Easy Login Logout
easy-login-logout
Easy Login Logout Menus is the perfect plugin for websites which have login user or logout user.
Simple Login Logout
simple-login-logout
This simple plugin makes your life easier by adding a login and logout link to your navigation menu out of the box. It adds a login link with a " …
D3 Register Menus
d3-register-menus
Add multiple menus locations to your website for a seamless navigation experience. Creates primary & secondary navigation, sidebar, footer, and co …
Login Logout Menu & Redirect
lmscrafter-user-menu-redirects
Dynamic login menus, 7-level smart redirect engine, role-based menu visibility, and login analytics. All in one plugin.
Primary-Login-Logout-Menu
primary-login-logout-menu
This is an easy way to add Login/Logout link in primary menu with redirect user to specific URL, on login. This plugin willl adds Settings page ( Unde …
Login Logout Menu Developer Profile
11 plugins · 660K total installs
How We Detect Login Logout Menu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/login-logout-menu/classes/shortcodes.phpHTML / DOM Fingerprints
loginlinksdivlogin-linkslist:login-linkscategorychecklistform-no-clearLogin Logout Menu is a handy plugin which allows you to add login, logout, register and profile menu items in your selected menu.Main Login_Logout_Menu Class.Version variable.Instance variable.+18 morelogin_logout_menu<a href="javascript:void(0);" class="help" onclick="jQuery( '#login-logout-menu-help' ).toggle();">Help</a>