Notakey Provider for Two-Factor Security & Risk Analysis

wordpress.org/plugins/notakey-two-factor-extension

Reduce friction and improve security of Two-Factor Authentication using push-based Notakey Authenticator mobile application.

0 active installs v1.0.17 PHP 5.6+ WP 4.3+ Updated Unknown
authenticationlogintotptwo-factortwo-step
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Notakey Provider for Two-Factor Safe to Use in 2026?

Generally Safe

Score 100/100

Notakey Provider for Two-Factor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "notakey-two-factor-extension" v1.0.17 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by effectively utilizing prepared statements for SQL queries and properly escaping most output. There are no recorded vulnerabilities or CVEs, and the taint analysis shows no concerning flows, suggesting a generally well-written codebase in these areas. The plugin also includes a nonce check and a capability check, which are important security measures.

However, a significant concern arises from the static analysis, which reveals one AJAX handler without any authentication checks. This creates a direct entry point for potential attackers to interact with the plugin without proper authorization. While the total attack surface is small, this single unprotected entry point represents a clear security weakness that could be exploited. The absence of vulnerabilities in its history is positive but does not negate the presence of this exploitable flaw in the current version.

In conclusion, while the plugin has strengths in its handling of SQL and output, the unprotected AJAX handler presents a critical risk. This weakness overshadows the otherwise good security practices observed. It's crucial to address this unauthenticated entry point to improve the plugin's overall security posture.

Key Concerns

  • AJAX handler without auth check
Vulnerabilities
None known

Notakey Provider for Two-Factor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Notakey Provider for Two-Factor Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Notakey Provider for Two-Factor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
71 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped75 total outputs
Attack Surface
1 unprotected

Notakey Provider for Two-Factor Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

noprivwp_ajax_ntk_check_auth_statustwo-factor-notakey.php:570
WordPress Hooks 10
actionpersonal_options_updateclass-two-factor-notakey.php:34
actionedit_user_profile_updateclass-two-factor-notakey.php:35
actionadmin_noticesclass-two-factor-notakey.php:36
actionadmin_noticestwo-factor-notakey.php:416
filtertwo_factor_providerstwo-factor-notakey.php:564
filtertwo_factor_enabled_providers_for_usertwo-factor-notakey.php:567
actionplugins_loadedtwo-factor-notakey.php:573
actionadmin_menutwo-factor-notakey.php:576
actionadmin_inittwo-factor-notakey.php:579
actiondeleted_usertwo-factor-notakey.php:582
Maintenance & Trust

Notakey Provider for Two-Factor Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedUnknown
PHP min version5.6
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Notakey Provider for Two-Factor Developer Profile

notakey

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Notakey Provider for Two-Factor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/notakey-two-factor-extension/css/style.css/wp-content/plugins/notakey-two-factor-extension/js/script.js
Script Paths
/wp-content/plugins/notakey-two-factor-extension/js/script.js
Version Parameters
notakey-two-factor-extension/css/style.css?ver=notakey-two-factor-extension/js/script.js?ver=

HTML / DOM Fingerprints

JS Globals
ntk_two_factor_script_vars
REST Endpoints
/wp-json/notakey-two-factor/v1/auth-status
FAQ

Frequently Asked Questions about Notakey Provider for Two-Factor