
PassClip Auth for WordPress Security & Risk Analysis
wordpress.org/plugins/passclip-auth-for-wordpress"PassClip Auth" provides strong and easy authentication. "PassClip Auth for WordPress" is the plugin to launch PassClip Auth to Wo …
Is PassClip Auth for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100PassClip Auth for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'passclip-auth-for-wordpress' plugin, version 1.0.5, presents a generally positive security posture based on the static analysis. The plugin has no recorded vulnerabilities (CVEs), which is a strong indicator of a secure development history. It also demonstrates good practices by not utilizing dangerous functions and by executing all SQL queries using prepared statements. Furthermore, the absence of a significant attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events, significantly reduces the potential for external exploitation.
However, there are a few areas for concern. The taint analysis revealed three flows with unsanitized paths, albeit none were classified as critical or high severity. This indicates a potential for input sanitization weaknesses that could, in a different context or with different data, lead to vulnerabilities. Additionally, the output escaping is only 62% proper, which, while not critical given the limited attack surface, could still pose a risk for stored or reflected cross-site scripting if user-supplied data is displayed without adequate sanitization in certain contexts. The presence of two external HTTP requests also warrants attention to ensure these are made securely and to trusted endpoints.
In conclusion, 'passclip-auth-for-wordpress' v1.0.5 appears to be a relatively secure plugin, primarily due to its limited attack surface and clean vulnerability history. The key strengths are the lack of CVEs and the use of prepared statements for SQL. The weaknesses lie in the potential for unsanitized paths identified by taint analysis and incomplete output escaping, which, although not critical in this specific version's observed behavior, should be monitored in future releases.
Key Concerns
- Flows with unsanitized paths found in taint analysis
- Output escaping is only 62% properly escaped
- External HTTP requests present
PassClip Auth for WordPress Security Vulnerabilities
PassClip Auth for WordPress Code Analysis
Output Escaping
Data Flow Analysis
PassClip Auth for WordPress Attack Surface
WordPress Hooks 39
Maintenance & Trust
PassClip Auth for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
PassClip Auth for WordPress Alternatives
4Login for Secure And Smart Access
4login-for-secure-and-smart-access
4Login will give you an easy and powerful authentication (connect to an external server for authentication).
Flavor 2FA
flavor-2fa
Lightweight two-factor authentication that just works. Protect your WordPress site with authenticator apps or email codes in under 2 minutes.
SecureAuth Authenticator 2FA
secureauth-authenticator-2fa
Adds TOTP-based two-factor authentication (2FA) via SecureAuth Authenticator to your WordPress login page.
Wordfence Login Security
wordfence-login-security
Secure your website with Wordfence Login Security, providing two-factor authentication, login and registration CAPTCHA, and XML-RPC protection.
Email OTP Login
email-otp-login
Adds OTP (One-Time Password) verification after login for enhanced security in WordPress. OTP is sent to the user's email.
PassClip Auth for WordPress Developer Profile
1 plugin · 10 total installs
How We Detect PassClip Auth for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/passclip-auth-for-wordpress/js/pca-login-form.js/wp-content/plugins/passclip-auth-for-wordpress/css/pca-login-form.css/wp-content/plugins/passclip-auth-for-wordpress/js/pca-login-form.jspassclip-auth-for-wordpress/js/pca-login-form.js?ver=passclip-auth-for-wordpress/css/pca-login-form.css?ver=HTML / DOM Fingerprints
woocommerce-form-rowwoocommerce-form-row--wideform-rowform-row-widewoocommerce-Inputwoocommerce-Input--textinput-textdata-pca-idpca_password_form