
Login With Security & Risk Analysis
wordpress.org/plugins/login-withAdd Google authentication to your WooCommerce store, allowing customers to log in with their Google accounts.
Is Login With Safe to Use in 2026?
Generally Safe
Score 100/100Login With has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'login-with' plugin v1.2 demonstrates a generally strong security posture based on the provided static analysis. The plugin exhibits good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and properly escaping the vast majority of its output. The presence of nonce checks on its two AJAX handlers is also a positive indicator of security awareness. The absence of any recorded vulnerabilities in its history further suggests a history of secure development.
However, a significant concern arises from the lack of capability checks on its entry points. While nonce checks are present, the absence of permission checks means that any authenticated user, regardless of their role or privileges, could potentially interact with the AJAX endpoints. This could be exploited if the AJAX actions perform sensitive operations that should be restricted to administrators or specific user roles. The plugin's reliance on external HTTP requests, while not explicitly flagged as a vulnerability here, is an area that warrants careful monitoring for potential supply chain risks or unintended data leakage if the external endpoints are compromised or behave maliciously.
In conclusion, the 'login-with' plugin v1.2 is built on a solid foundation of secure coding practices. The primary weakness lies in the missing capability checks, which opens a potential avenue for privilege escalation or unauthorized actions by less privileged users. The plugin's clean vulnerability history is commendable, but the identified security gaps in access control should be addressed to further harden its security.
Key Concerns
- Missing capability checks on entry points
Login With Security Vulnerabilities
Login With Code Analysis
Output Escaping
Login With Attack Surface
AJAX Handlers 2
WordPress Hooks 8
Maintenance & Trust
Login With Maintenance & Trust
Maintenance Signals
Community Trust
Login With Alternatives
Stitchz Social Login
stitchz-social-login
The Stitchz Social Login plugin adds the option to authenticate with one or more of the 22+ social identities providers supported by Stitchz.
Wapu Auth – Google Social Login for WordPress & WooCommerce
wapu-auth-social-login
Google Social Login for WordPress & WooCommerce -- free. Let users register and login with their Google account in one click. No passwords, no forms.
Nextend Social Login and Register
nextend-facebook-connect
One click registration & login plugin for Facebook, Google, X (formerly Twitter) and more. Quick setup and easy configuration.
Login for Google Apps
google-apps-login
Simple secure login and user management through your Google Workspace for WordPress (using oAuth2 and MFA if enabled).
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)
miniorange-login-openid
Social Login with Discord, Facebook, Google, Twitter, LinkedIn and 40+ apps. Social login with social share and comments. Free, fast & easy! WooCo …
Login With Developer Profile
1 plugin · 20 total installs
How We Detect Login With
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/login-with/css/style.css/wp-content/plugins/login-with/images/google-login.png/wp-content/plugins/login-with/images/google-login.pnglogin-with/css/style.css?ver=1.2.0login-with/images/google-login.png?ver=1.2.0HTML / DOM Fingerprints
login-with-button-imagelogin-with-buttonlogin-with-containerlogin-with-dividerdata-login-with-googlestaseo_login_success<div class="login-with-container"><a href="" class="login-with-button" id="login-with-button"><img src="