
Login or Logout Menu Item Security & Risk Analysis
wordpress.org/plugins/login-or-logout-menu-itemAdd a dynamic "Login" or "Logout" menu item to any WordPress Menu and control redirects.
Is Login or Logout Menu Item Safe to Use in 2026?
Generally Safe
Score 100/100Login or Logout Menu Item has a strong security track record. Known vulnerabilities have been patched promptly.
The login-or-logout-menu-item plugin v1.3.0 exhibits a generally good security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is a significant strength. Furthermore, the presence of nonce and capability checks, along with the complete use of prepared statements for SQL, indicates a developer's awareness of common WordPress security pitfalls. Taint analysis also reveals no critical or high-severity unsanitized flows, further bolstering confidence in its code quality.
However, there are a few areas of concern that temper an otherwise positive assessment. The fact that 33% of output is not properly escaped is a potential weakness, as it could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is outputted without sufficient sanitization. While the attack surface is currently zero, this is largely due to the lack of certain features like AJAX handlers or REST API routes, which might be desirable for full functionality. The plugin does have a history of a medium-severity vulnerability (Open Redirect), and while it is currently patched, it suggests that past development practices were not entirely flawless and a single past vulnerability can indicate a need for continued vigilance.
In conclusion, the plugin demonstrates a solid foundation of secure coding practices, especially concerning its interaction with the database and its attack surface management. The main area for improvement lies in ensuring all output is properly escaped to mitigate potential XSS risks. The historical vulnerability, though resolved, serves as a reminder to maintain rigorous security testing and code reviews.
Key Concerns
- Unescaped output found
- Past medium vulnerability (Open Redirect)
Login or Logout Menu Item Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Login or Logout Menu Item <= 1.1.1 - Unauthenticated Settings Update
Login or Logout Menu Item Code Analysis
Output Escaping
Data Flow Analysis
Login or Logout Menu Item Attack Surface
WordPress Hooks 9
Maintenance & Trust
Login or Logout Menu Item Maintenance & Trust
Maintenance Signals
Community Trust
Login or Logout Menu Item Alternatives
Login Logout Menu
login-logout-menu
Login Logout Menu is a handy plugin which allows you to add login, logout, register and profile menu items in your selected menu.
Menu Based Sidebar
menu-based-sidebar
Displays child menu items in the sidebar based on the currently selected parent menu item.
Easy Login Logout
easy-login-logout
Easy Login Logout Menus is the perfect plugin for websites which have login user or logout user.
Simple Login Logout
simple-login-logout
This simple plugin makes your life easier by adding a login and logout link to your navigation menu out of the box. It adds a login link with a " …
WP LogInOut
wp-loginout
Show login or logout button on any menu based on user login or logout status dynamically.
Login or Logout Menu Item Developer Profile
5 plugins · 32K total installs
How We Detect Login or Logout Menu Item
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
loginlinksdivlolmi_spacerThanks goes to Juliobox for his work on the BAW Login/Logout Menu plugin on which this is basedThis program is free software; you can redistribute it and/or modify
it under the terms of the GNU General Public License, version 2, as
published by the Free Software Foundation.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.Add Login/Logout suggestion to REST API search results.
* This works with the Navigation block's link picker.data-lolmi-login-page-urldata-lolmi-login-redirect-urldata-lolmi-logout-redirect-urllolmi_login_page_urllolmi_login_redirect_urllolmi_logout_redirect_url/wp/v2/search