
FIDO-certified Passwordless biometric login Security & Risk Analysis
wordpress.org/plugins/loginid-directwebFIDO-certified strong authentication in 5 clicks. Go passwordless and eliminate account takeovers and fraud.
Is FIDO-certified Passwordless biometric login Safe to Use in 2026?
Generally Safe
Score 85/100FIDO-certified Passwordless biometric login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "loginid-directweb" v1.1.0 demonstrates several good security practices. The code analysis shows a high percentage of properly escaped output and 100% of SQL queries using prepared statements, which are crucial for preventing common web vulnerabilities. The absence of dangerous functions, file operations, and any recorded vulnerabilities in its history are positive indicators of a generally secure codebase. However, there are notable concerns regarding its attack surface. Three out of four AJAX handlers lack authentication checks, presenting a significant risk of unauthorized access or manipulation. While taint analysis and known CVEs are clean, this lack of authorization on critical entry points could be exploited by attackers to perform actions they shouldn't be able to. The presence of external HTTP requests, though only one, also warrants attention as it could potentially be a vector for further compromise if not handled securely.
Key Concerns
- AJAX handlers without authorization
- External HTTP requests
FIDO-certified Passwordless biometric login Security Vulnerabilities
FIDO-certified Passwordless biometric login Code Analysis
Output Escaping
FIDO-certified Passwordless biometric login Attack Surface
AJAX Handlers 4
WordPress Hooks 16
Maintenance & Trust
FIDO-certified Passwordless biometric login Maintenance & Trust
Maintenance Signals
Community Trust
FIDO-certified Passwordless biometric login Alternatives
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Solid Security – Password, Two Factor Authentication, and Brute Force Protection
better-wp-security
Harden your site security with Login Security, Two-Factor Authentication (2FA), Vulnerability Scanner, Firewall, and more. Formerly iThemes Security.
Limit Login Attempts
limit-login-attempts
Limit rate of login attempts, including by way of cookies, for each IP. Fully customizable.
Two Factor
two-factor
Enable Two-Factor Authentication (2FA) using time-based one-time passwords (TOTP), Universal 2nd Factor (U2F), email, and backup verification codes.
WPS Limit Login
wps-limit-login
WPS Limit login limit connection attempts by IP address
FIDO-certified Passwordless biometric login Developer Profile
1 plugin · 20 total installs
How We Detect FIDO-certified Passwordless biometric login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/loginid-directweb/dist/js/loginid-directweb.js/wp-content/plugins/loginid-directweb/dist/css/loginid-directweb.css/wp-content/plugins/loginid-directweb/dist/js/loginid-directweb.jsloginid-directweb/dist/js/loginid-directweb.js?ver=loginid-directweb/dist/css/loginid-directweb.css?ver=HTML / DOM Fingerprints
window.loginid_dw_datavar loginid_dw_data