
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Security & Risk Analysis
wordpress.org/plugins/miniorange-login-openidSocial Login with Discord, Facebook, Google, Twitter, LinkedIn and 40+ apps. Social login with social share and comments. Free, fast & easy! WooCo …
Is miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Safe to Use in 2026?
Use With Caution
Score 56/100miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'miniorange-login-openid' plugin exhibits a mixed security posture. While it demonstrates strong practices in SQL query sanitization (94% prepared statements) and output escaping (100% properly escaped), significant concerns arise from its attack surface. A substantial 18 out of 24 entry points, primarily AJAX handlers, lack authentication checks, presenting a clear avenue for unauthorized actions. Furthermore, the plugin has a concerning history of documented vulnerabilities, including 9 known CVEs, with one critical and four high-severity issues remaining unpatched. The common vulnerability types, such as Remote File Inclusion, Improper Authentication, and Cross-Site Scripting, suggest recurring weaknesses in input validation and access control mechanisms. The presence of 2 high-severity taint flows with unsanitized paths, despite the overall low count, adds to the potential for exploitable weaknesses. While the plugin's adherence to secure output handling is commendable, the exposed AJAX endpoints and the unresolved historical vulnerabilities paint a picture of a plugin that requires immediate attention to secure its broader attack surface and address its persistent security flaws.
Key Concerns
- Unprotected AJAX handlers
- Unpatched critical CVE
- Unpatched high severity CVEs (x4)
- High severity taint flows (x2)
- Vulnerability history (multiple critical/high)
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Security Vulnerabilities
CVEs by Year
Severity Breakdown
9 total CVEs
Social Login and Register <= 7.7.0 - Authenticated (Administrator+) Local File Inclusion
WordPress Social Login and Register <= 7.6.10 - Unauthenticated Local File Inclusion
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon <= 200.3.9 - Authentication Bypass
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.6 - Authenticated (Subscriber+) Privilege Escalation
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.5.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.5.14 - Cross-Site Request Forgery
WordPress Social Login and Register <= 7.6.0 - Missing Authorization to Unauthenticated Arbitrary Content Deletion
WordPress Social Login and Register <=7.5.12 - Missing Authorization to Plugin Settings Update
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Attack Surface
AJAX Handlers 18
Shortcodes 6
WordPress Hooks 39
Maintenance & Trust
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Maintenance & Trust
Maintenance Signals
Community Trust
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Alternatives
UsersWP – Social Login
userswp-social-login
Social Login addon for UsersWP.
Happy Social Login
happy-social-login
Enables user authentication through various social media accounts. Login through Google, Facebook, LinkedIn, GitHub and more.
Nextend Social Login and Register
nextend-facebook-connect
One click registration & login plugin for Facebook, Google, X (formerly Twitter) and more. Quick setup and easy configuration.
Social Media Widget
social-media-widget
Adds links to all of your social media and sharing site profiles. Tons of icons come in 3 sizes, 4 icon styles, and 4 animations.
Tagembed: Embed Twitter Feed, Google Reviews, YouTube Videos, TikTok, RSS Feed & More Social Media Feeds
tagembed-widget
Collect & Embed Instagram Feed, Embed Facebook Feed, Embed YouTube Videos, Embed Twitter Feed, Google Reviews & 15+ Social Media Feed on website.
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Developer Profile
38 plugins · 83K total installs
How We Detect miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/miniorange-login-openid/includes/css/mo_openid_admin.css/wp-content/plugins/miniorange-login-openid/includes/css/mo_openid_social_login.css/wp-content/plugins/miniorange-login-openid/includes/js/mo_openid_social_login.js/wp-content/plugins/miniorange-login-openid/includes/js/mo_openid_admin.js/wp-content/plugins/miniorange-login-openid/includes/js/mo_openid_profile_completion.js/wp-content/plugins/miniorange-login-openid/includes/js/mo_social_comment.js/wp-content/plugins/miniorange-login-openid/includes/js/mo_openid_admin_script.js/wp-content/plugins/miniorange-login-openid/includes/js/mo_openid_social_login.js/wp-content/plugins/miniorange-login-openid/includes/js/mo_openid_admin.js/wp-content/plugins/miniorange-login-openid/includes/js/mo_openid_profile_completion.js/wp-content/plugins/miniorange-login-openid/includes/js/mo_social_comment.js/wp-content/plugins/miniorange-login-openid/includes/js/mo_openid_admin_script.jsminiorange-login-openid/includes/css/mo_openid_admin.css?ver=miniorange-login-openid/includes/css/mo_openid_social_login.css?ver=miniorange-login-openid/includes/js/mo_openid_social_login.js?ver=miniorange-login-openid/includes/js/mo_openid_admin.js?ver=miniorange-login-openid/includes/js/mo_openid_profile_completion.js?ver=miniorange-login-openid/includes/js/mo_social_comment.js?ver=miniorange-login-openid/includes/js/mo_openid_admin_script.js?ver=HTML / DOM Fingerprints
mo_openid_social_login_parent_divmo_openid_social_login_main_divmo_openid_social_login_facebookmo_openid_social_login_googlemo_openid_social_login_twittermo_openid_social_login_linkedinmo_openid_social_login_applemo_openid_social_login_amazon+51 more<!-- Added by miniOrange Social Login plugin --><!-- IMPORTANT: Add this code in your theme's footer.php file, before the closing </body> tag --><!-- PLEASE READ THE DOCUMENTATION --><!-- If you are getting ERROR: Invalid State parameter, make sure to check your session handling. -->+23 moredata-plugin-urldata-app-iddata-app-namedata-app-keydata-app-secretdata-redirect-uri+32 moremo_openid_social_login_varsmo_openid_social_comment_varsmo_openid_share_varsmo_openid_login_widget_vars/wp-json/mo-openid-sso/v1/login/wp-json/mo-openid-sso/v1/share/wp-json/mo-openid-sso/v1/comment[miniorange_social_login][miniorange_social_sharing][miniorange_social_sharing_vertical][miniorange_social_custom_fields]