
Multidots Passkey Login – Passwordless Login for WordPress Security & Risk Analysis
wordpress.org/plugins/multidots-passkey-loginPasswordless login for WordPress with Passkeys. Enable Touch ID, Face ID, and security keys for seamless, phishing-resistant authentication.
Is Multidots Passkey Login – Passwordless Login for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100Multidots Passkey Login – Passwordless Login for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The multidots-passkey-login plugin v1.1 demonstrates a generally strong security posture, with excellent adherence to secure coding practices. The complete absence of dangerous functions, all SQL queries utilizing prepared statements, and a near-perfect rate of output escaping are significant strengths. Furthermore, the plugin has no recorded vulnerability history, indicating a well-maintained and secure codebase. The presence of numerous nonce and capability checks further bolsters its defenses against common WordPress attacks.
However, a notable concern is the presence of one REST API route without permission callbacks. While the overall attack surface is moderate, this single unprotected entry point could potentially be exploited if it handles sensitive data or allows for unauthorized actions. The static analysis did not reveal any critical or high severity taint flows, which is a positive sign, but the lack of taint analysis flows analyzed (0) means this aspect of security is not fully validated. The absence of bundled libraries is also a positive, reducing the risk of using outdated components.
In conclusion, the plugin is commendably secure with robust coding practices. The primary area for improvement and the sole deduction stems from the single unprotected REST API route. While the risk is currently low due to the absence of known vulnerabilities and taint issues, it represents a potential point of failure that should be addressed to maintain its high security standard.
Key Concerns
- REST API route without permission callbacks
Multidots Passkey Login – Passwordless Login for WordPress Security Vulnerabilities
Multidots Passkey Login – Passwordless Login for WordPress Release Timeline
Multidots Passkey Login – Passwordless Login for WordPress Code Analysis
SQL Query Safety
Output Escaping
Multidots Passkey Login – Passwordless Login for WordPress Attack Surface
AJAX Handlers 9
REST API Routes 7
Shortcodes 2
WordPress Hooks 20
Scheduled Events 1
Maintenance & Trust
Multidots Passkey Login – Passwordless Login for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Multidots Passkey Login – Passwordless Login for WordPress Alternatives
Beyond Identity Passwordless
beyond-identity-passwordless
A passwordless solution that allows users and admins to log into a WordPress website using passkeys with Beyond Identity.
Secure Passkeys
secure-passkeys
Secure Passkeys is a powerful WordPress plugin that enables passwordless authentication using WebAuthn technology.
Biometric Authentication
biometric-authentication
Passkeys are a safer and easier alternative to passwords. Simply use your fingerprint or face ID to log in with ease.
Keyless Auth – Login without Passwords
keyless-auth
Secure, passwordless authentication for WordPress. Your users login via magic email links – no passwords to remember or forget.
Bye Bye Passwords
bye-bye-passwords
Enable passwordless authentication for WordPress using WebAuthn/Passkeys. More secure, more convenient.
Multidots Passkey Login – Passwordless Login for WordPress Developer Profile
9 plugins · 220 total installs
How We Detect Multidots Passkey Login – Passwordless Login for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/multidots-passkey-login/assets/css/mdlogin-passkey-frontend.css/wp-content/plugins/multidots-passkey-login/assets/css/mdlogin-passkey-backend.css/wp-content/plugins/multidots-passkey-login/assets/js/mdlogin-passkey-frontend.js/wp-content/plugins/multidots-passkey-login/assets/js/mdlogin-passkey-backend.jsmultidots-passkey-login/assets/css/mdlogin-passkey-frontend.css?ver=multidots-passkey-login/assets/css/mdlogin-passkey-backend.css?ver=multidots-passkey-login/assets/js/mdlogin-passkey-frontend.js?ver=multidots-passkey-login/assets/js/mdlogin-passkey-backend.js?ver=HTML / DOM Fingerprints
mdlogin-passkey-login-formmdlogin-passkey-registration-formmdlogin-passkey-manage-credentials-formdata-mdlogin-passkey-noncedata-mdlogin-passkey-user-iddata-mdlogin-passkey-actionmdlogin_passkey_frontend_paramsmdlogin_passkey_backend_params/wp-json/mdlogin-passkey/v1/register-challenge/wp-json/mdlogin-passkey/v1/register-response/wp-json/mdlogin-passkey/v1/login-challenge/wp-json/mdlogin-passkey/v1/login-response/wp-json/mdlogin-passkey/v1/delete-credential/wp-json/mdlogin-passkey/v1/create-credential[mdlogin_passkey_login_form][mdlogin_passkey_registration_form][mdlogin_passkey_manage_credentials_form]