
Login Monitor Security & Risk Analysis
wordpress.org/plugins/login-monitorDisplays current logged in users in administration screens in real time.
Is Login Monitor Safe to Use in 2026?
Generally Safe
Score 100/100Login Monitor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'login-monitor' plugin v1.0.3 exhibits a mixed security posture. On the positive side, its code analysis reveals no dangerous functions, all SQL queries use prepared statements, and outputs are properly escaped. Furthermore, there is no recorded vulnerability history, suggesting a lack of publicly known exploits. However, a significant concern arises from the single AJAX handler that lacks authentication checks. This creates a direct entry point for potential attackers to interact with the plugin without proper authorization, which could lead to unexpected behavior or exploitation depending on the functionality of that handler.
The taint analysis did not reveal any issues, which is a good sign. However, the absence of nonce checks, while not directly flagged as a deduction due to the presence of a capability check (though the details of that check are not provided), is a common oversight that can sometimes accompany unprotected AJAX endpoints. Given the sole unprotected entry point and the lack of any recorded vulnerabilities to learn from, the primary risk lies in the potential for an unauthenticated attacker to leverage this AJAX handler. While no vulnerabilities have been reported, this unprotected endpoint represents a significant potential weakness that should be addressed.
Key Concerns
- AJAX handler without auth checks
- Missing nonce checks on AJAX
Login Monitor Security Vulnerabilities
Login Monitor Code Analysis
SQL Query Safety
Login Monitor Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
Login Monitor Maintenance & Trust
Maintenance Signals
Community Trust
Login Monitor Alternatives
Admin User Control
admin-user-control
This plugin adds a useful feature to the administration screen that allows administrators to control the users involved in their operations.
Disable User Login
disable-user-login
Provides the ability to disable user accounts and prevent them from logging in.
Simple Login Log
simple-login-log
This plugin keeps a log of WordPress user logins. Offers user and date filtering, and export features.
Expire Users
expire-users
Set expiry dates for user logins.
Expire User Passwords
expire-user-passwords
Require certain users to change their passwords on a regular basis.
Login Monitor Developer Profile
20 plugins · 100 total installs
How We Detect Login Monitor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/login-monitor/css/login-monitor.css/wp-content/plugins/login-monitor/css/login-monitor.min.css/wp-content/plugins/login-monitor/js/login-monitor.js/wp-content/plugins/login-monitor/js/login-monitor.min.js/wp-content/plugins/login-monitor/js/login-monitor.js/wp-content/plugins/login-monitor/js/login-monitor.min.jslogin-monitor.css?ver=login-monitor.min.css?ver=login-monitor.js?ver=login-monitor.min.js?ver=HTML / DOM Fingerprints
ab-iconab-labellm-cntlm-listLOGIN_MONITOR_CONST/wp-json/login-monitor/