Login with Donbaler OAuth Security & Risk Analysis

wordpress.org/plugins/login-with-donbaler-oauth

افزونه ورود به وردپرس توسط حساب کاربری دنبالر ...

10 active installs v1.1.1 PHP + WP 3.0.1+ Updated Jun 2, 2015
apidonbaleroauth%d8%af%d9%86%d8%a8%d8%a7%d9%84%d8%b1
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Login with Donbaler OAuth Safe to Use in 2026?

Generally Safe

Score 85/100

Login with Donbaler OAuth has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "login-with-donbaler-oauth" plugin v1.1.1 exhibits a generally positive security posture based on the provided static analysis. The absence of dangerous functions, SQL queries without prepared statements, and file operations is commendable. The limited attack surface, with only one shortcode and no unprotected AJAX handlers or REST API routes, further contributes to a reduced risk profile. However, the analysis does reveal some areas for improvement. The lack of nonce checks and capability checks is a significant concern, as it could potentially expose functionality to unauthorized access if the shortcode or other entry points are manipulated. While the vulnerability history is clean, suggesting good past practices or low visibility, it doesn't negate the inherent risks identified in the code itself.

Overall, the plugin is strong in preventing common web vulnerabilities like SQL injection and insecure file handling. The absence of known vulnerabilities is a good sign. The primary weakness lies in the lack of robust access control mechanisms for its entry points, specifically the shortcode. This could be a target for attackers seeking to exploit unexpected behavior or information disclosure. Therefore, while the plugin is not inherently dangerous, the identified gaps in security checks warrant attention to ensure continued security.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Only 67% of output properly escaped
Vulnerabilities
None known

Login with Donbaler OAuth Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Login with Donbaler OAuth Release Timeline

v1.1.1Current
v1.1
v1.0
Code Analysis
Analyzed Mar 17, 2026

Login with Donbaler OAuth Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

67% escaped6 total outputs
Attack Surface

Login with Donbaler OAuth Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[donbaler-oauth] index.php:131
WordPress Hooks 3
actionadmin_menuindex.php:27
actionadmin_initindex.php:99
filterlogin_messageindex.php:129
Maintenance & Trust

Login with Donbaler OAuth Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedJun 2, 2015
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Login with Donbaler OAuth Developer Profile

Nima Saberi

5 plugins · 130 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Login with Donbaler OAuth

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
acc_login_form
Shortcode Output
[donbaler-oauth]
FAQ

Frequently Asked Questions about Login with Donbaler OAuth