Logto – User Authentication and Authorization Security & Risk Analysis

wordpress.org/plugins/logto

Enable beautiful and secure user authentication, including passwordless, social login, single sign-on, multi-factor authentication (MFA), and more.

20 active installs v1.0.1 PHP 8.1+ WP 6.0+ Updated Unknown
loginoauthoidcsamlsso
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Logto – User Authentication and Authorization Safe to Use in 2026?

Generally Safe

Score 100/100

Logto – User Authentication and Authorization has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The logto v1.0.1 plugin exhibits an exceptionally strong security posture based on the provided static analysis. The absence of any identified attack surface points, dangerous functions, unescaped output, file operations, or external HTTP requests is highly commendable and suggests meticulous development practices aimed at minimizing potential vulnerabilities. The complete reliance on prepared statements for any potential SQL queries further solidifies this positive assessment, indicating robust data sanitization against SQL injection. The lack of any recorded CVEs in its history, spanning all severity levels, further reinforces the impression of a secure plugin that has maintained its integrity over time.

While the static analysis reveals no immediate concerns, the total absence of nonce checks and capability checks, despite the plugin having a zero-point attack surface, warrants a slight reservation. Although no entry points were found to exploit, best practices typically involve implementing these checks for any potential future expansion or unexpected interactions. The bundled Guzzle library, while not inherently a vulnerability, does represent a dependency that could, in the future, inherit vulnerabilities from its own ecosystem. However, based on the current data, this plugin is evaluated as highly secure with no direct exploitable flaws identified.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Bundled library (Guzzle) potential future risk
Vulnerabilities
None known

Logto – User Authentication and Authorization Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Logto – User Authentication and Authorization Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
109 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

100% escaped109 total outputs
Attack Surface

Logto – User Authentication and Authorization Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actioninitsrc\LogtoPlugin.php:40
actionlogin_initsrc\LogtoPlugin.php:44
actionwp_logoutsrc\LogtoPlugin.php:45
actiontemplate_redirectsrc\LogtoPlugin.php:46
actionuser_profile_update_errorssrc\LogtoPlugin.php:47
actionplugins_loadedsrc\LogtoPlugin.php:48
actionadmin_menusrc\LogtoPluginAdminDashboard.php:16
actionadmin_enqueue_scriptssrc\LogtoPluginAdminDashboard.php:60
actionadmin_enqueue_scriptssrc\LogtoPluginAdminDashboard.php:81
actionadmin_noticessrc\LogtoPluginAdminDashboard.php:85
Maintenance & Trust

Logto – User Authentication and Authorization Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version8.1
Downloads846

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Logto – User Authentication and Authorization Developer Profile

logto

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Logto – User Authentication and Authorization

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/logto/assets/admin-menu.css/wp-content/plugins/logto/assets/admin-settings.css

HTML / DOM Fingerprints

Data Attributes
data-logto-endpointdata-logto-client-iddata-logto-redirect-uridata-logto-scopedata-logto-extra-paramsdata-logto-post-sign-out-redirect-uri+2 more
JS Globals
logtoLogto
FAQ

Frequently Asked Questions about Logto – User Authentication and Authorization