
Login by Magic Security & Risk Analysis
wordpress.org/plugins/magiclabsLogin by Magic plugin replaces the standard WordPress login form with one powered by Magic that enables passwordless email magic link login.
Is Login by Magic Safe to Use in 2026?
Generally Safe
Score 85/100Login by Magic has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The magiclabs v1.0.4 plugin exhibits a generally good security posture based on the static analysis. The plugin has a small attack surface with no unprotected entry points (AJAX, REST API, shortcodes, or cron events). Notably, there are no dangerous functions used, all SQL queries are prepared, and there are no file operations or external HTTP requests, which are significant security strengths. However, a concern arises from the output escaping, where 67% of outputs are properly escaped, leaving 33% potentially unescaped. This could present a Cross-Site Scripting (XSS) risk if user-supplied data is directly outputted without proper sanitization. The plugin's vulnerability history is clean, with zero recorded CVEs. This, combined with the lack of critical taint analysis findings, suggests a proactive approach to security or a limited scope of functionality. While the lack of explicit capability and nonce checks is a weakness, the absence of direct vulnerabilities in the analyzed code and the limited attack surface mitigate this risk in this specific version.
Key Concerns
- Output escaping not fully implemented
- Missing nonce checks on AJAX
- Missing capability checks
Login by Magic Security Vulnerabilities
Login by Magic Code Analysis
Output Escaping
Login by Magic Attack Surface
REST API Routes 1
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Login by Magic Maintenance & Trust
Maintenance Signals
Community Trust
Login by Magic Alternatives
Dolutech Passwordless Login
dolutech-passwordless-login
Permite login seguro sem senha com tecnologia passwordless e autenticação de dois fatores (2FA) via TOTP.
Elevation Magic Link Login
elevation-magic-link
Add a secure, passwordless login option to the default WordPress login form.
LoginEase
loginease
Passwordless login via secure magic links on the WordPress login form.
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Limit Login Attempts
limit-login-attempts
Limit rate of login attempts, including by way of cookies, for each IP. Fully customizable.
Login by Magic Developer Profile
1 plugin · 20 total installs
How We Detect Login by Magic
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/magiclabs/assets/css/magic-login.css/wp-content/plugins/magiclabs/assets/js/magic-login.js/wp-content/plugins/magiclabs/assets/js/magic-login.jsmagiclabs/assets/css/magic-login.css?ver=magiclabs/assets/js/magic-login.js?ver=HTML / DOM Fingerprints
magic-login-formmagic-login-buttondata-magic-login-client-idMagicLink/wp-json/magic/v1/auth[magic_login]