
Login with GitHub Security & Risk Analysis
wordpress.org/plugins/login-with-githubMinimal plugin that allows WordPress users to log in using GitHub.
Is Login with GitHub Safe to Use in 2026?
Generally Safe
Score 100/100Login with GitHub has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The login-with-github plugin v1.0.3 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for SQL, and a high percentage of properly escaped output are all positive indicators. Furthermore, the lack of external HTTP requests and file operations reduces the potential for common attack vectors. The plugin also has no recorded vulnerabilities, suggesting a history of secure development or a lack of active exploitation. However, a significant concern arises from the complete absence of nonce checks and capability checks across all entry points, including its single shortcode. While there are no unprotected entry points listed, the lack of these fundamental WordPress security mechanisms leaves the plugin vulnerable to Cross-Site Request Forgery (CSRF) attacks and unauthorized privilege escalation if an attacker can trick a logged-in user into triggering the shortcode's functionality without their explicit consent. The bundled Guzzle library, while not inherently a vulnerability, also introduces a potential risk if it is an outdated version, as it could contain known security flaws.
Key Concerns
- Missing nonce checks on all entry points
- Missing capability checks on all entry points
- Bundled library (Guzzle) without version info
Login with GitHub Security Vulnerabilities
Login with GitHub Code Analysis
Bundled Libraries
Output Escaping
Login with GitHub Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Login with GitHub Maintenance & Trust
Maintenance Signals
Community Trust
Login with GitHub Alternatives
Log in with Google
login-with-google
Minimal plugin that allows WordPress users to log in using Google.
Login for Google Apps
google-apps-login
Simple secure login and user management through your Google Workspace for WordPress (using oAuth2 and MFA if enabled).
BlaatLogin: OAuth
blaatschaap-oauth
This plugin turns your WordPress website into an OAuth Consumer. It allowsallows your users to sign in with any OAuth provider.
Secufor_OAuth
wpoauth
Secufor_OAuth is a WordPress plugin that enables Single Sign-On (SSO) functionality using the OAuth protocol.
JWT Authentication for WP REST API
jwt-authentication-for-wp-rest-api
Extends the WP REST API using JSON Web Tokens Authentication as an authentication method.
Login with GitHub Developer Profile
1 plugin · 0 total installs
How We Detect Login with GitHub
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/login-with-github/assets/css/bootstrap.min.css/wp-content/plugins/login-with-github/assets/js/bootstrap.bundle.min.js/wp-content/plugins/login-with-github/assets/js/bootstrap.bundle.min.jslogin-with-github/assets/css/bootstrap.min.css?ver=login-with-github/assets/js/bootstrap.bundle.min.js?ver=HTML / DOM Fingerprints
bi-githubdata-bs-toggledata-bs-target[lwg_auth_button]