Active Directory/LDAP Integration for Cloud & Shared Hosting Platforms Security & Risk Analysis

wordpress.org/plugins/miniorange-wp-ldap-login

Active Directory integration/LDAP integration enables authentication & login for WordPress sites on Shared Hosting like Bluehost, GoDaddy, SiteGro …

50 active installs v6.1.3 PHP 5.2.0+ WP 5.0+ Updated Nov 29, 2025
active-directoryactive-directory-integrationauthenticationldapldap-authentication
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Active Directory/LDAP Integration for Cloud & Shared Hosting Platforms Safe to Use in 2026?

Generally Safe

Score 100/100

Active Directory/LDAP Integration for Cloud & Shared Hosting Platforms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The static analysis of the miniorange-wp-ldap-login plugin v6.1.3 reveals a generally strong security posture. The plugin exhibits excellent practices with 100% of its output properly escaped and a significant portion of its SQL queries utilizing prepared statements. Furthermore, the absence of known CVEs and a clean vulnerability history is highly commendable, suggesting a commitment to security by the developers.

However, there are areas for concern. The taint analysis indicates three flows with unsanitized paths, which, while not classified as critical or high severity, warrant attention. These could potentially lead to vulnerabilities if user input is not properly handled in these specific code paths. The plugin also has a limited attack surface as reported, with no directly exposed entry points like unprotected AJAX handlers or REST API routes, which is a positive sign. The presence of file operations and external HTTP requests, while not inherently insecure, always introduces potential vectors that should be rigorously reviewed.

In conclusion, the plugin demonstrates good security fundamentals and a healthy track record. The primary areas to focus on for improvement are the identified unsanitized paths in the taint analysis. Addressing these proactively will further strengthen the plugin's security and maintain its strong reputation.

Key Concerns

  • Flows with unsanitized paths found
Vulnerabilities
None known

Active Directory/LDAP Integration for Cloud & Shared Hosting Platforms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Active Directory/LDAP Integration for Cloud & Shared Hosting Platforms Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
4 prepared
Unescaped Output
2
473 escaped
Nonce Checks
38
Capability Checks
1
File Operations
2
External Requests
14
Bundled Libraries
0

SQL Query Safety

50% prepared8 total queries

Output Escaping

100% escaped475 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

5 flows3 with unsanitized paths
mo_ldap_cloud_save_options (handlers\class-mo-ldap-cloud-save-options-handler.php:288)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Active Directory/LDAP Integration for Cloud & Shared Hosting Platforms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actionadmin_menuclass-mo-ldap-cloud-login.php:94
actionadmin_enqueue_scriptsclass-mo-ldap-cloud-login.php:95
actionadmin_enqueue_scriptsclass-mo-ldap-cloud-login.php:96
actionadmin_footerclass-mo-ldap-cloud-login.php:98
actionwpclass-mo-ldap-cloud-login.php:101
actionwpclass-mo-ldap-cloud-login.php:107
filterauthenticatehandlers\class-mo-ldap-cloud-login-handler.php:46
filterlogin_redirecthandlers\class-mo-ldap-cloud-login-handler.php:47
actionshow_user_profilehandlers\class-mo-ldap-cloud-login-handler.php:48
actionedit_user_profilehandlers\class-mo-ldap-cloud-login-handler.php:49
filterlogin_messagehandlers\class-mo-ldap-cloud-login-handler.php:262
actionadmin_inithandlers\class-mo-ldap-cloud-save-options-handler.php:47
actioninithandlers\class-mo-ldap-cloud-save-options-handler.php:48
actionadmin_noticesutils\class-mo-ldap-cloud-utils.php:108
actionadmin_noticesutils\class-mo-ldap-cloud-utils.php:182
Maintenance & Trust

Active Directory/LDAP Integration for Cloud & Shared Hosting Platforms Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 29, 2025
PHP min version5.2.0
Downloads25K

Community Trust

Rating98/100
Number of ratings39
Active installs50
Developer Profile

Active Directory/LDAP Integration for Cloud & Shared Hosting Platforms Developer Profile

miniOrange

38 plugins · 83K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
324 days
View full developer profile
Detection Fingerprints

How We Detect Active Directory/LDAP Integration for Cloud & Shared Hosting Platforms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/miniorange-wp-ldap-login/css/miniorange-ldap-login-styles.css/wp-content/plugins/miniorange-wp-ldap-login/js/miniorange-ldap-login-scripts.js/wp-content/plugins/miniorange-wp-ldap-login/js/miniorange-ldap-login-scripts-new.js/wp-content/plugins/miniorange-wp-ldap-login/js/miniorange-ldap-login-admin-scripts.js
Script Paths
/wp-content/plugins/miniorange-wp-ldap-login/js/miniorange-ldap-login-scripts.js/wp-content/plugins/miniorange-wp-ldap-login/js/miniorange-ldap-login-scripts-new.js/wp-content/plugins/miniorange-wp-ldap-login/js/miniorange-ldap-login-admin-scripts.js
Version Parameters
miniorange-wp-ldap-login/css/miniorange-ldap-login-styles.css?ver=miniorange-wp-ldap-login/js/miniorange-ldap-login-scripts.js?ver=miniorange-wp-ldap-login/js/miniorange-ldap-login-scripts-new.js?ver=miniorange-wp-ldap-login/js/miniorange-ldap-login-admin-scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
miniorange-ldap-login-wrappermo-ldap-cloud-login-notice
HTML Comments
<!-- A pointer to the plugin directory to include files --><!-- Displays the feedback form --><!-- MO LDAP Cloud Login Feedback Request --><!-- MO LDAP Cloud Login Feedback Request -->+1 more
Data Attributes
data-nonce
JS Globals
mo_ldap_cloud_ajax_object
FAQ

Frequently Asked Questions about Active Directory/LDAP Integration for Cloud & Shared Hosting Platforms