
OAuth client Single Sign On for WordPress ( OAuth 2.0 SSO ) Security & Risk Analysis
wordpress.org/plugins/oauth-client-for-user-authenticationWordPress OAuth client SSO ( OAuth 2.0 & OpenID SSO ) plugin allows login ( Single Sign On ) with your OAuth Servers like AWS Cognito, Amazon, Az …
Is OAuth client Single Sign On for WordPress ( OAuth 2.0 SSO ) Safe to Use in 2026?
Mostly Safe
Score 83/100OAuth client Single Sign On for WordPress ( OAuth 2.0 SSO ) is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved. Keep it updated.
The "oauth-client-for-user-authentication" plugin v3.1.1 presents a mixed security posture. On the positive side, the static analysis reveals a lack of direct attack vectors such as AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication. Furthermore, SQL queries are exclusively using prepared statements, and a high percentage of output is properly escaped. However, several concerning signals exist. The presence of 5 flows with unsanitized paths, despite no critical or high severity taint flows being reported, warrants attention as it suggests potential for vulnerabilities if these paths are ever exposed to user input. The plugin also makes 4 external HTTP requests, which could be exploited if not handled securely. A significant concern is the plugin's history of 2 high severity vulnerabilities, specifically Missing Authorization and Cross-site Scripting. While currently unpatched CVEs are 0, the recurring nature of these vulnerability types in the past indicates a potential for similar weaknesses to re-emerge in future versions if code review and secure coding practices are not rigorously applied. The lack of capability checks in the code signals is also a weakness, as it implies that some functionalities might be accessible to users who should not have access.
Key Concerns
- 5 unsanitized paths in taint analysis
- 4 external HTTP requests
- 2 high severity vulnerabilities in history
- 0 capability checks
OAuth client Single Sign On for WordPress ( OAuth 2.0 SSO ) Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
OAuth client Single Sign On for WordPress ( OAuth 2.0 SSO ) <= 3.0.3 - Missing Authorization
OAuth client Single Sign On for WordPress ( OAuth 2.0 SSO ) <= 3.0.1 - Cross-Site Scripting
OAuth client Single Sign On for WordPress ( OAuth 2.0 SSO ) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
OAuth client Single Sign On for WordPress ( OAuth 2.0 SSO ) Attack Surface
WordPress Hooks 4
Maintenance & Trust
OAuth client Single Sign On for WordPress ( OAuth 2.0 SSO ) Maintenance & Trust
Maintenance Signals
Community Trust
OAuth client Single Sign On for WordPress ( OAuth 2.0 SSO ) Alternatives
JWT Authentication for WP REST API
jwt-authentication-for-wp-rest-api
Extends the WP REST API using JSON Web Tokens Authentication as an authentication method.
Login for Google Apps
google-apps-login
Simple secure login and user management through your Google Workspace for WordPress (using oAuth2 and MFA if enabled).
Log in with Google
login-with-google
Minimal plugin that allows WordPress users to log in using Google.
Authorizer
authorizer
Authorizer limits login attempts, restricts access to specific users, and authenticates against external sources (OAuth2, Google, LDAP, or CAS).
Keyring
keyring
An authentication framework that handles authorization/communication with most popular web services.
OAuth client Single Sign On for WordPress ( OAuth 2.0 SSO ) Developer Profile
1 plugin · 200 total installs
How We Detect OAuth client Single Sign On for WordPress ( OAuth 2.0 SSO )
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/oauth-client-for-user-authentication/Assets/css/style.css/wp-content/plugins/oauth-client-for-user-authentication/Assets/js/script.js/wp-content/plugins/oauth-client-for-user-authentication/Assets/js/script.js/oauth-client-for-user-authentication/Assets/css/style.css?ver=/oauth-client-for-user-authentication/Assets/js/script.js?ver=HTML / DOM Fingerprints
buttons_styleoauthclient_layout_containerdata-nonceoc_oauthclient_layout_script