
Login with Donbaler OAuth Security & Risk Analysis
wordpress.org/plugins/login-with-donbaler-oauthافزونه ورود به وردپرس توسط حساب کاربری دنبالر ...
Is Login with Donbaler OAuth Safe to Use in 2026?
Generally Safe
Score 85/100Login with Donbaler OAuth has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "login-with-donbaler-oauth" plugin v1.1.1 exhibits a generally positive security posture based on the provided static analysis. The absence of dangerous functions, SQL queries without prepared statements, and file operations is commendable. The limited attack surface, with only one shortcode and no unprotected AJAX handlers or REST API routes, further contributes to a reduced risk profile. However, the analysis does reveal some areas for improvement. The lack of nonce checks and capability checks is a significant concern, as it could potentially expose functionality to unauthorized access if the shortcode or other entry points are manipulated. While the vulnerability history is clean, suggesting good past practices or low visibility, it doesn't negate the inherent risks identified in the code itself.
Overall, the plugin is strong in preventing common web vulnerabilities like SQL injection and insecure file handling. The absence of known vulnerabilities is a good sign. The primary weakness lies in the lack of robust access control mechanisms for its entry points, specifically the shortcode. This could be a target for attackers seeking to exploit unexpected behavior or information disclosure. Therefore, while the plugin is not inherently dangerous, the identified gaps in security checks warrant attention to ensure continued security.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Only 67% of output properly escaped
Login with Donbaler OAuth Security Vulnerabilities
Login with Donbaler OAuth Release Timeline
Login with Donbaler OAuth Code Analysis
Output Escaping
Login with Donbaler OAuth Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Login with Donbaler OAuth Maintenance & Trust
Maintenance Signals
Community Trust
Login with Donbaler OAuth Alternatives
JWT Authentication for WP REST API
jwt-authentication-for-wp-rest-api
Extends the WP REST API using JSON Web Tokens Authentication as an authentication method.
Tweets Widget
tweets-widget
Tweets Widget compatible with the new Twitter API 1.1
Linkedin_Oauth
linkedin-oauth
Linkedin_Oauth allows users to login/register into your wordpress using their linkedin account, uses shortcodes.
LinkedIn Profile Synchronizer Tool
lips
This tool downloads your LinkedIn® profile and maintains a selectable page on your WordPress installation.
WordPress REST API – Authentication Broker
rest-api-broker
Used together with the WP REST API OAuth 1.0a Server plugin, this allows the WP RET API Authentication Broker
Login with Donbaler OAuth Developer Profile
5 plugins · 130 total installs
How We Detect Login with Donbaler OAuth
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
acc_login_form[donbaler-oauth]