
NHR Secure – Login Security, Firewall, 2FA & Audit Log Security & Risk Analysis
wordpress.org/plugins/nhrrob-secureA lightweight WordPress security plugin to protect your admin area with a custom login URL, hide debug logs, limit login attempts, and add 2FA.
Is NHR Secure – Login Security, Firewall, 2FA & Audit Log Safe to Use in 2026?
Generally Safe
Score 100/100NHR Secure – Login Security, Firewall, 2FA & Audit Log has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "nhrrob-secure" v1.3.1 plugin exhibits a generally strong security posture, particularly in its handling of web requests and data output. The absence of any AJAX handlers, shortcodes, or unprotected REST API routes significantly limits the potential attack surface. Furthermore, the plugin demonstrates excellent output escaping practices, ensuring that all 45 observed outputs are properly sanitized, mitigating risks associated with cross-site scripting (XSS) vulnerabilities. The presence of numerous capability checks (18) also indicates a good understanding of WordPress's permission system, suggesting that access to sensitive functions is likely restricted to authorized users. Taint analysis revealed no critical or high-severity issues, and the plugin has no recorded vulnerability history, which are positive indicators of its security reliability.
However, a few areas warrant attention. While the majority of SQL queries utilize prepared statements (56%), the remaining 44% that do not could potentially be vulnerable to SQL injection if they handle user-supplied input without proper sanitization. The single file operation could also be a point of concern depending on its implementation and whether it handles external data without validation. While the plugin includes nonce checks, their limited number (2) might suggest that not all sensitive operations are adequately protected, especially in light of the 14 REST API routes. Overall, "nhrrob-secure" appears to be a well-developed plugin with a focus on secure coding, but attention to the un-prepared SQL queries and the scope of nonce protection would further enhance its security.
Key Concerns
- SQL queries without prepared statements
- File operations without clear sanitization context
- Limited nonce checks relative to entry points
NHR Secure – Login Security, Firewall, 2FA & Audit Log Security Vulnerabilities
NHR Secure – Login Security, Firewall, 2FA & Audit Log Release Timeline
NHR Secure – Login Security, Firewall, 2FA & Audit Log Code Analysis
SQL Query Safety
Output Escaping
NHR Secure – Login Security, Firewall, 2FA & Audit Log Attack Surface
REST API Routes 14
WordPress Hooks 47
Scheduled Events 2
Maintenance & Trust
NHR Secure – Login Security, Firewall, 2FA & Audit Log Maintenance & Trust
Maintenance Signals
Community Trust
NHR Secure – Login Security, Firewall, 2FA & Audit Log Alternatives
Liveupx Security
liveupx-security
Complete WordPress security — Firewall, 2FA, Malware Scanner, Vulnerability Scanner, Login Protection, Security Headers. 100% free.
Wordfence Security – Firewall, Malware Scan, and Login Security
wordfence
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team. Make security a priority with Wordfence.
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
really-simple-ssl
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate.
Limit Login Attempts Reloaded – Login Security, 2FA, Brute Force Protection & Firewall
limit-login-attempts-reloaded
Stop password guessing attacks, secure WooCommerce, block bad IPs, block by countries (Pro), and add email 2FA. Lightweight with better performance.
Two Factor
two-factor
Enable Two-Factor Authentication (2FA) using time-based one-time passwords (TOTP), email, and backup verification codes.
NHR Secure – Login Security, Firewall, 2FA & Audit Log Developer Profile
4 plugins · 180 total installs
How We Detect NHR Secure – Login Security, Firewall, 2FA & Audit Log
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nhrrob-secure/build/admin.css/wp-content/plugins/nhrrob-secure/build/admin.js/wp-content/plugins/nhrrob-secure/build/profile.css/wp-content/plugins/nhrrob-secure/build/profile.js/wp-content/plugins/nhrrob-secure/build/admin.js/wp-content/plugins/nhrrob-secure/build/profile.jsnhrrob-secure/build/admin.css?ver=nhrrob-secure/build/admin.js?ver=nhrrob-secure/build/profile.css?ver=nhrrob-secure/build/profile.js?ver=HTML / DOM Fingerprints
nhrrob-secure-settings-root/wp-json/nhrrob-secure/v1