
WP Login and Register using JWT Security & Risk Analysis
wordpress.org/plugins/login-register-using-jwtWordPress login (WordPress Single Sign-On) using JWT token obtained from other WordPress sites or any other application. Synchronize user sessions bet …
Is WP Login and Register using JWT Safe to Use in 2026?
Generally Safe
Score 99/100WP Login and Register using JWT has a strong security track record. Known vulnerabilities have been patched promptly.
The 'login-register-using-jwt' plugin version 3.2.0 exhibits a mixed security posture. While it demonstrates good practices like using prepared statements for SQL queries and a high percentage of properly escaped outputs, significant concerns remain. The presence of one unprotected AJAX handler represents a direct attack vector. Taint analysis indicates unsanitized paths, suggesting potential for unexpected behavior or vulnerabilities if user input is not handled carefully, although no critical or high severity flows were detected. The plugin's history includes one medium-severity vulnerability, which was reportedly patched, and the absence of currently unpatched CVEs is a positive sign. However, the common vulnerability type of 'Missing Authorization' in its history, coupled with the unprotected AJAX handler in the current static analysis, suggests a recurring weakness that warrants attention. Overall, the plugin has strengths in data handling but requires vigilance regarding access control for its entry points.
Key Concerns
- Unprotected AJAX handler
- Taint analysis shows unsanitized paths
- Past medium vulnerability (though patched)
WP Login and Register using JWT Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Login and Register using JWT <= 3.0.0 - Missing Authorization to Authenticated (Subscriber+) API Key Exposure
WP Login and Register using JWT Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
WP Login and Register using JWT Attack Surface
AJAX Handlers 1
WordPress Hooks 12
Maintenance & Trust
WP Login and Register using JWT Maintenance & Trust
Maintenance Signals
Community Trust
WP Login and Register using JWT Alternatives
Simple JWT Login – Allows you to use JWT on REST endpoints.
simple-jwt-login
Enhance the WordPress REST API with JWT authentication for secure access by mobile apps, external sites, and third-party services.
Hippoo Auth
hippoo-auth
Extend your WooCommerce Store API with secure authentication endpoints for social and manual login. Ideal for custom apps, headless themes, or fronten …
Simple JWT Auth
simple-jwt-auth
Extends the WP REST API using JSON Web Tokens for robust authentication, providing a secure and reliable way to access and manage WordPress data.
TokenLink SSO Login for Zendesk
tokenlink-sso-login-for-zendesk
Provides secure JWT-based single sign-on (SSO) between WordPress and Zendesk. No third-party plugins, no tracking, no bloat. Totally free.
Twelve Legs Marketing SSO
twelve-legs-marketing-sso
Single sign-on plugin for WordPress that accepts RS256 JWTs from the TWL SSO application for secure authentication.
WP Login and Register using JWT Developer Profile
38 plugins · 83K total installs
How We Detect WP Login and Register using JWT
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/login-register-using-jwt/resources/css/style_settings.min.css/wp-content/plugins/login-register-using-jwt/resources/css/phone.min.css/wp-content/plugins/login-register-using-jwt/resources/css/bootstrap/bootstrap.min.css/wp-content/plugins/login-register-using-jwt/resources/js/settings.min.js/wp-content/plugins/login-register-using-jwt/resources/js/phone.min.jslogin-register-using-jwt/resources/css/style_settings.min.css?ver=login-register-using-jwt/resources/css/phone.min.css?ver=login-register-using-jwt/resources/css/bootstrap/bootstrap.min.css?ver=login-register-using-jwt/resources/js/settings.min.js?ver=login-register-using-jwt/resources/js/phone.min.js?ver=HTML / DOM Fingerprints
mo_jwt_admin_settings_stylemo_jwt_admin_settings_phone_stylemo-jwt_licensedata-tabMJ_URL