
Login with Cognito Security & Risk Analysis
wordpress.org/plugins/login-with-cognitoWordPress Login with Cognito plugin allows Login ( Single Sign-On ) to WordPress using AWS Cognito account credentials. You can Login to your WordPres …
Is Login with Cognito Safe to Use in 2026?
Generally Safe
Score 97/100Login with Cognito has a strong security track record. Known vulnerabilities have been patched promptly.
The "login-with-cognito" plugin v1.5.3 exhibits a mixed security posture. On the positive side, static analysis indicates good practices such as 100% use of prepared statements for SQL queries, a high percentage of properly escaped output, and the presence of nonce and capability checks. There are no direct indications of critical or high-severity vulnerabilities within the current static analysis of the code itself, with zero unprotected entry points. However, the plugin's history of three known CVEs, including a past critical vulnerability related to Authentication Bypass and Cross-site Scripting, is a significant concern. While currently unpatched vulnerabilities are zero, this history suggests a recurring pattern of exploitable flaws that have required significant attention in the past. The presence of unsanitized paths in taint analysis, even without critical or high severity, warrants attention as it could potentially lead to vulnerabilities if not handled carefully.
Overall, while the current version of the plugin appears to have addressed immediate critical issues and follows some good security practices, the historical pattern of vulnerabilities cannot be ignored. The plugin's reliance on external HTTP requests (15) and the use of a bundled library (DataTables) could also introduce risks if not managed properly. The past critical vulnerabilities, even if patched, indicate that the codebase has been susceptible to serious flaws, demanding continued vigilance and thorough auditing. Therefore, while the immediate static analysis is somewhat reassuring, the historical context necessitates a cautious approach to its security.
Key Concerns
- Past critical vulnerability history
- Past medium vulnerability history (2 instances)
- Taint flows with unsanitized paths
- Bundled library (DataTables)
Login with Cognito Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Login with Cognito <= 1.4.8 - Authenticated (Admin+) Stored Cross-Site Scripting
Login with Cognito <= 1.4.6 - Authentication Bypass
Multiple miniOrange Plugins (Various Version) - Reflected Cross-Site Scripting
Login with Cognito Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Login with Cognito Attack Surface
Shortcodes 1
WordPress Hooks 17
Maintenance & Trust
Login with Cognito Maintenance & Trust
Maintenance Signals
Community Trust
Login with Cognito Alternatives
Gatey – Login & SSO with Amazon Cognito
gatey
Drag-and-drop Amazon Cognito integration: 22-language screens, Single Sign-on, Multi-Factor Authentication, secure JWT tokens, and more.
OAuth Single Sign On – SSO (OAuth Client)
miniorange-login-with-eve-online-google-facebook
WordPress SSO (Single Sign On) with Azure, Azure B2C, Cognito, Okta, Classlink, Discord, Clever, Keycloak, OAuth & OpenID Providers [24/7 SUPPORT].
SMTP for Amazon SES – YaySMTP
smtp-amazon-ses
Send WordPress emails through Amazon SES server using YaySMTP
Amazon Link Engine
amazon-link-engine
Automatically localize and affiliate Amazon product links to improve user experience, increase conversions and earn global commissions.
Amazon Product in a Post Plugin
amazon-product-in-a-post-plugin
Add formatted Amazon Products to any page or post using the Amazon Product Advertising API.
Login with Cognito Developer Profile
38 plugins · 83K total installs
How We Detect Login with Cognito
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/login-with-cognito/resources/css/style.css/wp-content/plugins/login-with-cognito/resources/js/login-with-cognito.jslogin-with-cognito/resources/css/style.css?ver=login-with-cognito/resources/js/login-with-cognito.js?ver=HTML / DOM Fingerprints
mo_oauth_loginminiOrange_login_buttonminiOrange_login_form<!-- MoCognito OAuth class --><!-- Constructor --><!-- Success Message --><!-- Feedback Request -->+7 moredata-plugin-name="login-with-cognito"data-plugin-version="1.5.3"window.moCognitoOAuth[mo_oauth_login]