
Rundiz OAuth Security & Risk Analysis
wordpress.org/plugins/okv-oauthUse OAuth such as Google, LINE to login and register.
Is Rundiz OAuth Safe to Use in 2026?
Generally Safe
Score 100/100Rundiz OAuth has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The okv-oauth plugin v1.6.4 presents a generally positive security posture, adhering to several best practices such as using prepared statements for all SQL queries and implementing nonce checks. The absence of known CVEs and a clean vulnerability history further contribute to this favorable assessment. However, the static analysis reveals areas that warrant attention. Specifically, the taint analysis shows that all 9 analyzed flows have unsanitized paths, with no critical or high severity issues identified but this still indicates a potential for unexpected behavior or unintended data manipulation if not handled carefully in subsequent logic.
The plugin's output escaping is also a concern, with 36% of outputs not properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not sufficiently sanitized before being displayed. While the attack surface appears minimal with no direct entry points like AJAX handlers or REST API routes exposed without authentication, the presence of 8 external HTTP requests and one file operation, coupled with the unsanitized taint flows and imperfect output escaping, suggests a need for vigilance and further review to ensure these operations do not introduce security weaknesses.
Key Concerns
- Unsanitized paths in taint flows
- Improper output escaping
- External HTTP requests present
- File operations present
Rundiz OAuth Security Vulnerabilities
Rundiz OAuth Code Analysis
Output Escaping
Data Flow Analysis
Rundiz OAuth Attack Surface
WordPress Hooks 49
Maintenance & Trust
Rundiz OAuth Maintenance & Trust
Maintenance Signals
Community Trust
Rundiz OAuth Alternatives
Social Login by BestWebSoft
social-login-bws
Add social media login, registration, and commenting to your WordPress website.
Wapu Auth – Google Social Login for WordPress & WooCommerce
wapu-auth-social-login
Google Social Login for WordPress & WooCommerce -- free. Let users register and login with their Google account in one click. No passwords, no forms.
Nextend Social Login and Register
nextend-facebook-connect
One click registration & login plugin for Facebook, Google, X (formerly Twitter) and more. Quick setup and easy configuration.
Login for Google Apps
google-apps-login
Simple secure login and user management through your Google Workspace for WordPress (using oAuth2 and MFA if enabled).
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)
miniorange-login-openid
Social Login with Discord, Facebook, Google, Twitter, LinkedIn and 40+ apps. Social login with social share and comments. Free, fast & easy! WooCo …
Rundiz OAuth Developer Profile
7 plugins · 2K total installs
How We Detect Rundiz OAuth
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/okv-oauth/assets/js/rd-oauth-adminnetworksettings.js/wp-content/plugins/okv-oauth/assets/css/rd-settings-tabs.css/wp-content/plugins/okv-oauth/assets/js/rd-settings-tabs.js/wp-content/plugins/okv-oauth/assets/css/rd-settings-customstyle.css/wp-content/plugins/okv-oauth/assets/js/rd-oauth-adminnetworksettings.js/wp-content/plugins/okv-oauth/assets/js/rd-settings-tabs.jsokv-oauth/assets/css/rd-settings-tabs.css?ver=okv-oauth/assets/js/rd-settings-tabs.js?ver=okv-oauth/assHTML / DOM Fingerprints
rd-oauth-settings-tabs-wrapdata-rd-oauth-provider-itemRdOauthAdminNetworkSettings