
Magic Link – Secure one click passwordless login Security & Risk Analysis
wordpress.org/plugins/magic-linkSecure one click passwordless login
Is Magic Link – Secure one click passwordless login Safe to Use in 2026?
Generally Safe
Score 100/100Magic Link – Secure one click passwordless login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The magic-link plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for all SQL queries, performing a significant number of nonce checks, and having no recorded vulnerability history. This suggests a developer who is aware of and attempts to implement common WordPress security measures. However, concerns arise from the static analysis. The plugin has an unprotected AJAX handler, representing a direct entry point without authentication, which is a significant risk. Furthermore, the taint analysis reveals two high-severity flows with unsanitized paths, indicating potential vulnerabilities where user input could be manipulated to affect application behavior. While the vulnerability history is clean, the presence of high-severity taint flows and an unprotected AJAX handler warrants attention.
Key Concerns
- Unprotected AJAX handler
- High severity unsanitized taint flows
- Taint flows with unsanitized paths
- Low percentage of properly escaped output
Magic Link – Secure one click passwordless login Security Vulnerabilities
Magic Link – Secure one click passwordless login Release Timeline
Magic Link – Secure one click passwordless login Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Magic Link – Secure one click passwordless login Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 27
Maintenance & Trust
Magic Link – Secure one click passwordless login Maintenance & Trust
Maintenance Signals
Community Trust
Magic Link – Secure one click passwordless login Alternatives
Magic Login – Passwordless Authentication for WordPress – Login Without Password
magic-login
Passwordless login for WordPress. Streamline the login process by sending magic links to your users.
Magic Login Link
magic-link-login
Enables the user to login without entering a password. Instead a mail with a login is sent.
Temporary Login Without Password
temporary-login-without-password
Create self-expiring, temporary admin accounts. Easily share direct login links (no need for username/password) with your developers or editors.
Temporary Login
temporary-login
Create a secure, temporary URL for easy access to your WP admin.
User Verification by PickPlugins
user-verification
Email verification for user registration to protect spam.
Magic Link – Secure one click passwordless login Developer Profile
15 plugins · 31K total installs
How We Detect Magic Link – Secure one click passwordless login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/magic-link/lite/dist/scripts/magic-link.js/wp-content/plugins/magic-link/lite/dist/styles/app.css/wp-content/plugins/magic-link/lite/dist/styles/magic-link-admin.css/wp-content/plugins/magic-link/lite/dist/scripts/magic-link.jsmagic-link/style.css?ver=magic-link/script.js?ver=magic-link-script?ver=magic-link-main?ver=magic-link-admin?ver=HTML / DOM Fingerprints
generate-magic-linkmagic-linkcopy-magic-linkdata-user-idmagicLinkAjaxmagicLinkAjax