
One Time Login Security & Risk Analysis
wordpress.org/plugins/one-time-loginUse WP-CLI to generate a one-time login URL for any user
Is One Time Login Safe to Use in 2026?
Generally Safe
Score 100/100One Time Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "one-time-login" plugin v0.4.0 exhibits a mixed security posture. On the positive side, the code demonstrates good practices by exclusively using prepared statements for SQL queries, ensuring proper output escaping, and avoiding file operations and external HTTP requests. The vulnerability history being clean, with no recorded CVEs, also suggests a degree of past diligence. However, significant concerns arise from the static analysis results. The plugin has a total of one entry point, which is identified as unprotected. This unprotected REST API route represents a direct avenue for potential exploitation if not properly secured by the application itself or other plugins.
Key Concerns
- Unprotected REST API route
One Time Login Security Vulnerabilities
One Time Login Code Analysis
One Time Login Attack Surface
REST API Routes 1
WordPress Hooks 3
Scheduled Events 1
Maintenance & Trust
One Time Login Maintenance & Trust
Maintenance Signals
Community Trust
One Time Login Alternatives
Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall
limit-login-attempts-reloaded
Block excessive login attempts and protect your site against brute force attacks. Simple, yet powerful tools to improve site performance.
WPS Hide Login
wps-hide-login
Change wp-login.php to anything you want.
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Loginizer
loginizer
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Security Optimizer – The All-In-One Protection Plugin
sg-security
Secure your WordPress site from brute-force attacks, threats, malware, and bots. Free to use and easy to set up.
One Time Login Developer Profile
9 plugins · 51K total installs
How We Detect One Time Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
/wp-json/one-time-login/v1/token