
Magic Login Link Security & Risk Analysis
wordpress.org/plugins/magic-link-loginEnables the user to login without entering a password. Instead a mail with a login is sent.
Is Magic Login Link Safe to Use in 2026?
Generally Safe
Score 85/100Magic Login Link has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The magic-link-login plugin, version 1.1.0, exhibits a mixed security posture. On the positive side, it utilizes prepared statements for all SQL queries and has no recorded vulnerability history, suggesting a generally stable codebase. However, significant concerns arise from the static analysis. The plugin exposes one AJAX handler without any authentication or capability checks, creating a direct entry point for potential unauthenticated actions. Furthermore, all observed output operations lack proper escaping, meaning user-supplied data displayed on the frontend could be vulnerable to cross-site scripting (XSS) attacks. The taint analysis also identified two flows with unsanitized paths, which, while not categorized as critical or high, are still concerning as they could lead to unexpected behavior or compromise if exploited in conjunction with other weaknesses.
Key Concerns
- AJAX handler without auth checks
- Output escaping missing
- Unsanitized paths in taint flows
Magic Login Link Security Vulnerabilities
Magic Login Link Code Analysis
Output Escaping
Data Flow Analysis
Magic Login Link Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Magic Login Link Maintenance & Trust
Maintenance Signals
Community Trust
Magic Login Link Alternatives
Magic Login – Passwordless Authentication for WordPress – Login Without Password
magic-login
Passwordless login for WordPress. Streamline the login process by sending magic links to your users.
Magic Link – Secure one click passwordless login
magic-link
Secure one click passwordless login
Temporary Login Without Password
temporary-login-without-password
Create self-expiring, temporary admin accounts. Easily share direct login links (no need for username/password) with your developers or editors.
VentraConnect – Social Login, Magic Link & Email OTP (Passwordless)
ventraconnect-social-login
Social login with 15+ providers plus passwordless login (Magic Link & Email OTP), with Guardrails to block spam registrations.
Temporary Login
temporary-login
Create a secure, temporary URL for easy access to your WP admin.
Magic Login Link Developer Profile
1 plugin · 80 total installs
How We Detect Magic Login Link
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/magic-link-login/css/login.css/wp-content/plugins/magic-link-login/js/login.js/wp-content/plugins/magic-link-login/js/login.jsmagic-link-login/css/login.css?ver=magic-link-login/js/login.js?ver=HTML / DOM Fingerprints
amc-magic-login-buttonamc-spark-oramc-spark-mail-input-wrapperid="amc-spark-mail-input"<a href="#">Magic Login</a>