
OneCode Login Security & Risk Analysis
wordpress.org/plugins/onecode-loginSimple and secure passwordless login using email verification codes. No passwords to remember, just enter your email and verify with a 6-digit code.
Is OneCode Login Safe to Use in 2026?
Generally Safe
Score 100/100OneCode Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "onecode-login" plugin v1.0.0 exhibits a generally good security posture regarding common WordPress vulnerabilities. The code analysis shows excellent practices with 100% of SQL queries using prepared statements and all output being properly escaped. Furthermore, there are no dangerous functions, file operations, or external HTTP requests detected. The presence of nonce and capability checks on entry points is also a positive sign. However, the taint analysis reveals a significant concern: all 7 analyzed flows have unsanitized paths, with 5 classified as high severity. This indicates that data processed by the plugin might not be sufficiently validated or cleansed, potentially leading to unexpected behavior or vulnerabilities if that data is user-controlled or originates from an untrusted source. The plugin also has no recorded vulnerability history, which is a strong positive, suggesting a history of secure development or a lack of past exploitation. Despite the promising foundation, the high number of unsanitized taint flows is a notable weakness that requires careful investigation and remediation.
Key Concerns
- High severity unsanitized taint flows
- Unsanitized paths in all taint flows
OneCode Login Security Vulnerabilities
OneCode Login Release Timeline
OneCode Login Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
OneCode Login Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 12
Scheduled Events 1
Maintenance & Trust
OneCode Login Maintenance & Trust
Maintenance Signals
Community Trust
OneCode Login Alternatives
Authyo Passwordless Login
authyo-passwordless-login
Enable secure OTP login for WordPress with passwordless authentication using email-based one-time passwords (OTP) powered by Authyo.
Password Less Login
password-less-login
A powerful and easy-to-use WordPress plugin for passwordless and OTP-based login.
User Verification by PickPlugins
user-verification
Email verification for user registration to protect spam.
Email OTP Authenticator – Login, Register, 2FA & Session Lock
email-otp-authenticator
An advanced OTP-powered plugin for Login, Registration, 2FA Protection and Dynamic Session Security. It is FAST, FRIENDLY, SMART, SMOOTH & SECURE.
Email OTP Login
email-otp-login
Adds OTP (One-Time Password) verification after login for enhanced security in WordPress. OTP is sent to the user's email.
OneCode Login Developer Profile
3 plugins · 230 total installs
How We Detect OneCode Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/onecode-login/assets/css/frontend.css/wp-content/plugins/onecode-login/assets/js/frontend.js/wp-content/plugins/onecode-login/assets/js/frontend.jsonecode-login.css?ver=frontend.js?ver=HTML / DOM Fingerprints
data-action-type="login_code"data-action-type="login_code_resend"data-action-type="login_code_verify"data-action-type="magic_link_request"onecodeLogin