
WP OAuth Server ( Login with WordPress ) Security & Risk Analysis
wordpress.org/plugins/miniorange-oauth-20-serverSingle Sign-On using WordPress - Login with WordPress to your application/sites using your WordPress account. [24/7 Support]
Is WP OAuth Server ( Login with WordPress ) Safe to Use in 2026?
Generally Safe
Score 98/100WP OAuth Server ( Login with WordPress ) has a strong security track record. Known vulnerabilities have been patched promptly.
The miniorange-oauth-20-server plugin, version 6.1.3, demonstrates generally good security practices with a strong emphasis on prepared statements for SQL queries and proper output escaping. The extensive use of nonce and capability checks further bolsters its security posture against common web vulnerabilities. The absence of known unpatched CVEs and the low number of total entry points are positive indicators.
However, the taint analysis reveals a significant concern with four flows identified as having unsanitized paths, all rated as high severity. This suggests a potential for vulnerabilities where user-controlled data is not adequately validated before being used in sensitive operations, possibly leading to information disclosure or unauthorized actions. While the plugin has a history of one critical CVE related to authentication bypass, the fact that it's currently patched is reassuring, but the nature of the past vulnerability is a flag for potential reoccurrence if similar coding patterns persist.
In conclusion, while the plugin excels in foundational security measures like SQL sanitization and output escaping, the presence of high-severity unsanitized paths in the taint analysis warrants careful investigation and remediation. The historical critical vulnerability also highlights the need for ongoing vigilance, even with a patched record.
Key Concerns
- High severity taint flows with unsanitized paths
- History of critical CVEs (though currently patched)
WP OAuth Server ( Login with WordPress ) Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP OAuth Server <= 3.0.4 - Authentication Bypass
WP OAuth Server ( Login with WordPress ) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP OAuth Server ( Login with WordPress ) Attack Surface
WordPress Hooks 12
Scheduled Events 1
Maintenance & Trust
WP OAuth Server ( Login with WordPress ) Maintenance & Trust
Maintenance Signals
Community Trust
WP OAuth Server ( Login with WordPress ) Alternatives
OpenID Connect Generic Client
daggerhart-openid-connect-generic
A simple client that provides SSO or opt-in authentication against a generic OAuth2 Server implementation.
WP OAuth Server (OAuth Authentication)
oauth2-provider
Adds Authentication through OAuth 2. Provides the ability for Single Sign On for websites & Mobile Applications.
OAuth client Single Sign On for WordPress ( OAuth 2.0 SSO )
oauth-client-for-user-authentication
WordPress OAuth client SSO ( OAuth 2.0 & OpenID SSO ) plugin allows login ( Single Sign On ) with your OAuth Servers like AWS Cognito, Amazon, Az …
OpenID Connect Server
openid-connect-server
Use OpenID Connect to log in to other webservices using your own WordPress.
Hellō Login
hello-login
Free and simple to setup plugin provides registration and login with the Hellō Wallet. Users choose from popular social login, email, or phone.
WP OAuth Server ( Login with WordPress ) Developer Profile
38 plugins · 83K total installs
How We Detect WP OAuth Server ( Login with WordPress )
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/miniorange-oauth-20-server/admin/css/all.css/wp-content/plugins/miniorange-oauth-20-server/admin/css/bulma.min.css/wp-content/plugins/miniorange-oauth-20-server/admin/css/bulma-switch.min.css/wp-content/plugins/miniorange-oauth-20-server/admin/css/bulma-tooltip.min.css/wp-content/plugins/miniorange-oauth-20-server/admin/css/intl-tel-input.css/wp-content/plugins/miniorange-oauth-20-server/admin/css/miniorange-oauth-20-server-admin.css/wp-content/plugins/miniorange-oauth-20-server/admin/css/security_notice.min.css/wp-content/plugins/miniorange-oauth-20-server/admin/js/miniorange-oauth-20-server-admin.js+1 moreminiorange-oauth-20-server/admin/css/all.css?ver=miniorange-oauth-20-server/admin/css/bulma.min.css?ver=miniorange-oauth-20-server/admin/css/bulma-switch.min.css?ver=miniorange-oauth-20-server/admin/css/bulma-tooltip.min.css?ver=miniorange-oauth-20-server/admin/css/intl-tel-input.css?ver=miniorange-oauth-20-server/admin/css/miniorange-oauth-20-server-admin.css?ver=miniorange-oauth-20-server/admin/css/security_notice.min.css?ver=miniorange-oauth-20-server/admin/js/miniorange-oauth-20-server-admin.js?ver=miniorange-oauth-20-server/admin/js/intl-tel-input.js?ver=HTML / DOM Fingerprints
miniorange-oauth-20-serverdata-plugin-name="miniorange-oauth-20-server"miniorange_oauth_server_adminmo_oauth_server_admin