
OpenID Connect Server Security & Risk Analysis
wordpress.org/plugins/openid-connect-serverUse OpenID Connect to log in to other webservices using your own WordPress.
Is OpenID Connect Server Safe to Use in 2026?
Generally Safe
Score 100/100OpenID Connect Server has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "openid-connect-server" v2.0.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is highly commendable. Furthermore, the plugin demonstrates excellent practice with 100% of its SQL queries using prepared statements and all output being properly escaped, which significantly mitigates common web vulnerabilities like SQL injection and cross-site scripting (XSS).
The static analysis reveals a very limited attack surface with no unprotected entry points. The presence of capability checks, although minimal, is a positive indicator of access control measures. The lack of any recorded CVEs or past vulnerabilities further reinforces the perception of a well-secured plugin, suggesting a history of diligent security development.
While the plugin's current state is excellent, a minor concern arises from the absence of nonce checks. While the identified entry points are protected by capability checks, the lack of nonces on AJAX handlers (though there are none in this version) or other potential interaction points means that if new interaction methods were introduced in the future without proper nonce implementation, they could theoretically be susceptible to CSRF attacks. However, given the current limited attack surface and the strong emphasis on prepared statements and output escaping, the overall risk is very low.
Key Concerns
- Missing nonce checks
OpenID Connect Server Security Vulnerabilities
OpenID Connect Server Code Analysis
SQL Query Safety
Output Escaping
OpenID Connect Server Attack Surface
WordPress Hooks 6
Scheduled Events 1
Maintenance & Trust
OpenID Connect Server Maintenance & Trust
Maintenance Signals
Community Trust
OpenID Connect Server Alternatives
WP OAuth Server ( Login with WordPress )
miniorange-oauth-20-server
Single Sign-On using WordPress - Login with WordPress to your application/sites using your WordPress account. [24/7 Support]
Scouting OpenID Connect
scouting-openid-connect
WordPress plugin for logging in with Scouting Nederland OpenID Connect Server.
VivoKey OpenID Connect
vivokey-openid-connect
Authenticate your WordPress account by scanning your VivoKey cryptobionic implant instead of using your username and password.
OpenID Connect Generic Client
daggerhart-openid-connect-generic
A simple client that provides SSO or opt-in authentication against a generic OAuth2 Server implementation.
OAuth Single Sign On – SSO (OAuth Client)
miniorange-login-with-eve-online-google-facebook
WordPress SSO (Single Sign On) with Azure, Azure B2C, Cognito, Okta, Classlink, Discord, Clever, Keycloak, OAuth & OpenID Providers [24/7 SUPPORT].
OpenID Connect Server Developer Profile
213 plugins · 19.2M total installs
How We Detect OpenID Connect Server
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/openid-connect-server/src/js/frontend.js/wp-content/plugins/openid-connect-server/src/js/frontend.jsopenid-connect-server/src/js/frontend.js?ver=HTML / DOM Fingerprints
window.oidcConfig/wp-json/openid-connect/authorization/wp-json/openid-connect/token/wp-json/openid-connect/userinfo/wp-json/openid-connect/jwks