
One Tap Google Sign in Security & Risk Analysis
wordpress.org/plugins/one-tap-google-sign-inAllows users to add Google One Tap Sign-in Or Sign-up to wordpress website.
Is One Tap Google Sign in Safe to Use in 2026?
Generally Safe
Score 85/100One Tap Google Sign in has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "one-tap-google-sign-in" plugin v1.4.1 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, or external HTTP requests is a significant positive. Furthermore, the high percentage of properly escaped output and the presence of nonce checks suggest good development practices for preventing common web vulnerabilities. The plugin also has a clean vulnerability history with no recorded CVEs, indicating a history of secure development and maintenance.
However, there are a few areas that warrant attention. The static analysis reveals a single shortcode, which is a potential entry point. While the total number of entry points is low and none are reported as unprotected, it's crucial that this shortcode is implemented securely and does not introduce any vulnerabilities. The lack of capability checks on any entry points, although not explicitly flagged as unprotected, is a weakness. Relying solely on nonce checks for all entry points might leave certain functionalities vulnerable if an attacker can bypass or manipulate the nonce mechanism. The bundled Guzzle library also presents a minor concern, as outdated bundled libraries can sometimes harbor vulnerabilities, though this is not confirmed by the provided data.
In conclusion, the plugin appears to be well-secured with good coding practices observed. The primary concerns are the potential implicit risks associated with the shortcode and the absence of capability checks on any entry points, which could be mitigated with further review. The clean vulnerability history is a strong indicator of the developer's commitment to security.
Key Concerns
- No capability checks on entry points
- Bundled library (Guzzle) present
One Tap Google Sign in Security Vulnerabilities
One Tap Google Sign in Release Timeline
One Tap Google Sign in Code Analysis
Bundled Libraries
Output Escaping
One Tap Google Sign in Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
One Tap Google Sign in Maintenance & Trust
Maintenance Signals
Community Trust
One Tap Google Sign in Alternatives
oneTap – Easy Google Sign In Prompt
onetap
oneTap - One Tab Google Sign In plugin allows you to get more users for your shop, directory, magazine, portal, and booking site.
Easy Social Login
easy-social-login
Easily integrate social login options into your WordPress site.
Nextend Social Login and Register
nextend-facebook-connect
One click registration & login plugin for Facebook, Google, X (formerly Twitter) and more. Quick setup and easy configuration.
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)
miniorange-login-openid
Social Login with Discord, Facebook, Google, Twitter, LinkedIn and 40+ apps. Social login with social share and comments. Free, fast & easy! WooCo …
UsersWP – Social Login
userswp-social-login
Social Login addon for UsersWP.
One Tap Google Sign in Developer Profile
1 plugin · 1K total installs
How We Detect One Tap Google Sign in
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/one-tap-google-sign-in/assets/css/style.css/wp-content/plugins/one-tap-google-sign-in/assets/js/main.jshttps://accounts.google.com/gsi/clientone-tap-google-sign-in/assets/css/style.css?ver=one-tap-google-sign-in/assets/js/main.js?ver=HTML / DOM Fingerprints
g_id_signindata-client_iddata-auto_selectdata-login_uridata-wpnoncedata-redirect_uridata-use_fedcm_for_prompt+7 moregotl_options/wp-json/[gotl_google_login_button]