Magefan Login As Customer Security & Risk Analysis

wordpress.org/plugins/magefan-login-as-customer

Easily log in as any customer from the WordPress admin. Perfect for support teams and store administrators.

0 active installs v1.0.0 PHP 7.4+ WP 5.0+ Updated Mar 19, 2026
adminloginsupportuserswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Magefan Login As Customer Safe to Use in 2026?

Generally Safe

Score 100/100

Magefan Login As Customer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "magefan-login-as-customer" plugin version 1.0.0 exhibits a generally positive security posture due to its adherence to several secure coding practices. Notably, it utilizes prepared statements for all SQL queries, boasts excellent output escaping (98%), and performs a reasonable number of capability checks (5). The absence of file operations and external HTTP requests further contributes to its defensibility. However, a significant concern arises from the presence of one AJAX handler that lacks authentication checks, creating a direct, unprotected entry point for potential attackers.

The taint analysis, while limited in scope (2 flows analyzed), reveals that both flows involved unsanitized paths. Although no critical or high severity issues were flagged, this indicates a potential for insecure handling of data that could be manipulated. The vulnerability history is clean, with no recorded CVEs, which is a strong positive indicator. This suggests the plugin has historically been maintained securely or has not been a target for exploitation.

In conclusion, while the plugin demonstrates good development habits in critical areas like database interaction and output sanitization, the unprotected AJAX handler presents a clear and immediate risk. The taint analysis findings, even without critical severity, warrant attention. This plugin is reasonably secure, but the identified unprotected entry point requires remediation to achieve a more robust security profile.

Key Concerns

  • Unprotected AJAX handler
  • Taint flows with unsanitized paths
Vulnerabilities
None known

Magefan Login As Customer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Magefan Login As Customer Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

Magefan Login As Customer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
15 prepared
Unescaped Output
1
63 escaped
Nonce Checks
1
Capability Checks
5
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared15 total queries

Output Escaping

98% escaped64 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
handle_magefan_lac (admin/class-admin.php:161)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Magefan Login As Customer Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_magefan_lacincludes/class-login-as-customer.php:74
WordPress Hooks 13
filtermanage_users_columnsincludes/class-login-as-customer.php:65
filtermanage_users_custom_columnincludes/class-login-as-customer.php:66
filtermanage_woocommerce_page_wc-orders_columnsincludes/class-login-as-customer.php:69
actionmanage_woocommerce_page_wc-orders_custom_columnincludes/class-login-as-customer.php:70
actionadmin_menuincludes/class-login-as-customer.php:77
actionadmin_initincludes/class-login-as-customer.php:78
actionadmin_enqueue_scriptsincludes/class-login-as-customer.php:81
actionadmin_bar_menuincludes/class-login-as-customer.php:84
actionadmin_noticesincludes/class-login-as-customer.php:85
actionwp_footerincludes/class-login-as-customer.php:86
actionwp_enqueue_scriptsincludes/class-login-as-customer.php:87
actionadmin_enqueue_scriptsincludes/class-login-as-customer.php:88
actionadmin_post_revert_magefan_lacincludes/class-login-as-customer.php:89
Maintenance & Trust

Magefan Login As Customer Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 19, 2026
PHP min version7.4
Downloads173

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Magefan Login As Customer Developer Profile

magefan

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Magefan Login As Customer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/magefan-login-as-customer/assets/css/admin.css/wp-content/plugins/magefan-login-as-customer/assets/js/admin.js
Script Paths
/wp-content/plugins/magefan-login-as-customer/assets/js/admin.js
Version Parameters
/wp-content/plugins/magefan-login-as-customer/assets/css/admin.css?ver=/wp-content/plugins/magefan-login-as-customer/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
login-as-customer-btnlogin-as-customer-spinner
Data Attributes
data-user-iddata-noncedata-username
FAQ

Frequently Asked Questions about Magefan Login As Customer