No Login by Email Address Security & Risk Analysis

wordpress.org/plugins/no-login-by-email-address

Removes the ability to login using the email address instead of the username.

1K active installs v1.3.0 PHP + WP 4.9+ Updated Jun 23, 2025
emailloginusername
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is No Login by Email Address Safe to Use in 2026?

Generally Safe

Score 100/100

No Login by Email Address has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The "no-login-by-email-address" v1.3.0 plugin exhibits an exceptionally clean static analysis report. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero-point attack surface. Furthermore, the code demonstrates excellent security hygiene with no dangerous functions, 100% prepared SQL statements, and 100% properly escaped output. No file operations, external HTTP requests, or bundled libraries are present, which minimizes common attack vectors.

Crucially, the absence of taint analysis findings indicates no detected vulnerabilities related to unsanitized data flows. The plugin's vulnerability history is also spotless, with no recorded CVEs of any severity. This comprehensive lack of security weaknesses in both static analysis and historical data suggests a very robust security posture for this specific version of the plugin.

While the current analysis presents a strong security profile, it is important to note that the absence of nonce and capability checks, along with a complete lack of entry points, makes it difficult to fully assess its security in a real-world operational context. However, based solely on the provided data, the plugin appears to be secure and well-developed from a security perspective.

Vulnerabilities
None known

No Login by Email Address Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

No Login by Email Address Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

No Login by Email Address Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filtergettextno-login-by-email-address.php:31
actionlogin_headno-login-by-email-address.php:34
filterlogin_form_defaultsno-login-by-email-address.php:46
filtergettextno-login-by-email-address.php:61
Maintenance & Trust

No Login by Email Address Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 23, 2025
PHP min version
Downloads12K

Community Trust

Rating100/100
Number of ratings4
Active installs1K
Developer Profile

No Login by Email Address Developer Profile

cubecolour

17 plugins · 21K total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect No Login by Email Address

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about No Login by Email Address