
Log in with Google Security & Risk Analysis
wordpress.org/plugins/login-with-googleMinimal plugin that allows WordPress users to log in using Google.
Is Log in with Google Safe to Use in 2026?
Generally Safe
Score 100/100Log in with Google has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "login-with-google" plugin version 1.4.2 exhibits a generally good security posture with several strong practices observed. The code analysis shows 100% of SQL queries use prepared statements and all output is properly escaped, indicating a robust defense against common injection and XSS vulnerabilities. Furthermore, there are no known CVEs associated with this plugin, suggesting a history of stable and secure development. The absence of dangerous functions, file operations, and taint analysis findings also contributes positively to its security profile.
However, a significant concern arises from the attack surface analysis, which reveals one AJAX handler that lacks authentication checks. This unprotected entry point represents a potential vulnerability that could be exploited by unauthenticated users to interact with the plugin's backend functionality. While the plugin has a clean vulnerability history, this single unprotected AJAX handler is a critical oversight that, if exploited, could lead to unintended consequences. The presence of capability checks being zero is also a point of concern, as it implies that even authenticated users might not be properly restricted in their actions if the unprotected AJAX handler were to be leveraged.
In conclusion, the plugin demonstrates strong fundamental security practices in its coding, particularly regarding SQL and output sanitization. The lack of historical vulnerabilities is a positive indicator. The primary weakness lies in the single unprotected AJAX endpoint, which significantly increases the risk profile despite other strengths. Addressing this unprotected entry point is crucial for improving the plugin's overall security.
Key Concerns
- Unprotected AJAX handler found
- No capability checks implemented
Log in with Google Security Vulnerabilities
Log in with Google Release Timeline
Log in with Google Code Analysis
Output Escaping
Log in with Google Attack Surface
AJAX Handlers 1
WordPress Hooks 21
Maintenance & Trust
Log in with Google Maintenance & Trust
Maintenance Signals
Community Trust
Log in with Google Alternatives
Login with GitHub
login-with-github
Minimal plugin that allows WordPress users to log in using GitHub.
Login for Google Apps
google-apps-login
Simple secure login and user management through your Google Workspace for WordPress (using oAuth2 and MFA if enabled).
BlaatLogin: OAuth
blaatschaap-oauth
This plugin turns your WordPress website into an OAuth Consumer. It allowsallows your users to sign in with any OAuth provider.
GOAuth
goauth
Go and OAuthenticate plugin for WordPress.
Keystone OIDC
keystone-oidc
Turn your WordPress site into an OpenID Connect (OIDC) identity provider. Manage clients through a simple admin panel.
Log in with Google Developer Profile
20 plugins · 218K total installs
How We Detect Log in with Google
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/login-with-google/build/css/button/style.css/wp-content/plugins/login-with-google/build/js/login.jsbuild/js/login.js