PassClip Auth for WordPress Security & Risk Analysis

wordpress.org/plugins/passclip-auth-for-wordpress

"PassClip Auth" provides strong and easy authentication. "PassClip Auth for WordPress" is the plugin to launch PassClip Auth to Wo …

10 active installs v1.0.5 PHP 5.3.3+ WP 4.5+ Updated Dec 27, 2019
2faloginotpsecuritytwo-factor-authentication
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PassClip Auth for WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

PassClip Auth for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The 'passclip-auth-for-wordpress' plugin, version 1.0.5, presents a generally positive security posture based on the static analysis. The plugin has no recorded vulnerabilities (CVEs), which is a strong indicator of a secure development history. It also demonstrates good practices by not utilizing dangerous functions and by executing all SQL queries using prepared statements. Furthermore, the absence of a significant attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events, significantly reduces the potential for external exploitation.

However, there are a few areas for concern. The taint analysis revealed three flows with unsanitized paths, albeit none were classified as critical or high severity. This indicates a potential for input sanitization weaknesses that could, in a different context or with different data, lead to vulnerabilities. Additionally, the output escaping is only 62% proper, which, while not critical given the limited attack surface, could still pose a risk for stored or reflected cross-site scripting if user-supplied data is displayed without adequate sanitization in certain contexts. The presence of two external HTTP requests also warrants attention to ensure these are made securely and to trusted endpoints.

In conclusion, 'passclip-auth-for-wordpress' v1.0.5 appears to be a relatively secure plugin, primarily due to its limited attack surface and clean vulnerability history. The key strengths are the lack of CVEs and the use of prepared statements for SQL. The weaknesses lie in the potential for unsanitized paths identified by taint analysis and incomplete output escaping, which, although not critical in this specific version's observed behavior, should be monitored in future releases.

Key Concerns

  • Flows with unsanitized paths found in taint analysis
  • Output escaping is only 62% properly escaped
  • External HTTP requests present
Vulnerabilities
None known

PassClip Auth for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

PassClip Auth for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
23
37 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

62% escaped60 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

6 flows3 with unsanitized paths
widget (class-passclip-auth-login-widget.php:18)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

PassClip Auth for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 39
actionwp_loadedclass-passclip-auth-login-widget.php:9
actionwidgets_initclass-passclip-auth-login-widget.php:130
filtermanage_users_custom_columnclass-pca-users-list-table.php:15
filterusers_list_table_query_argsclass-pca-users-list-table.php:16
actionwoocommerce_login_form_endpassclip-auth-for-woo.php:25
actionwoocommerce_edit_account_form_startpassclip-auth-for-woo.php:45
actionwoocommerce_edit_account_formpassclip-auth-for-woo.php:57
actionwoocommerce_before_edit_account_formpassclip-auth-for-woo.php:78
filterwoocommerce_get_username_from_emailpassclip-auth-for-woo.php:92
filterwoocommerce_save_account_details_required_fieldspassclip-auth-for-woo.php:106
actionwoocommerce_save_account_details_errorspassclip-auth-for-woo.php:123
filteroption_woocommerce_enable_myaccount_registrationpassclip-auth-for-woo.php:136
filteroption_woocommerce_registration_generate_passwordpassclip-auth-for-woo.php:150
filteroption_woocommerce_enable_signup_and_login_from_checkoutpassclip-auth-for-woo.php:164
actionlogin_enqueue_scriptspassclip-auth-login-form.php:25
actionlogin_formpassclip-auth-login-form.php:55
filterwp_login_errorspassclip-auth-login-form.php:105
filterlogin_redirectpassclip-auth-login.php:177
filterlogin_redirectpassclip-auth-login.php:181
filterlogin_redirectpassclip-auth-login.php:219
actionlostpassword_postpassclip-auth-login.php:515
actionplugins_loadedpassclip-auth-options.php:117
actionadmin_noticespassclip-auth-options.php:176
filtershow_password_fieldspassclip-auth-user-edit.php:40
actionedit_user_profilepassclip-auth-user-edit.php:76
actionuser_edit_form_tagpassclip-auth-user-edit.php:171
actionadmin_print_styles-profile.phppassclip-auth-user-edit.php:182
actionadmin_print_scripts-profile.phppassclip-auth-user-edit.php:194
actionpersonal_options_updatepassclip-auth-user-edit.php:288
actionpersonal_options_updatepassclip-auth-user-edit.php:301
filterscreen_options_show_screenpassclip-auth-users.php:20
filterpassclip_auth_page_pca_manage_users_per_pagepassclip-auth-users.php:41
filterauthenticatepassclip-auth.php:65
actioninitpassclip-auth.php:69
filterinitpassclip-auth.php:82
actionadmin_menupassclip-auth.php:119
actionadmin_headpassclip-auth.php:129
filterplugin_action_linkspassclip-auth.php:153
filterpca_create_userpassclip-auth.php:199
Maintenance & Trust

PassClip Auth for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedDec 27, 2019
PHP min version5.3.3
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

PassClip Auth for WordPress Developer Profile

Passlogy

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PassClip Auth for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/passclip-auth-for-wordpress/js/pca-login-form.js/wp-content/plugins/passclip-auth-for-wordpress/css/pca-login-form.css
Script Paths
/wp-content/plugins/passclip-auth-for-wordpress/js/pca-login-form.js
Version Parameters
passclip-auth-for-wordpress/js/pca-login-form.js?ver=passclip-auth-for-wordpress/css/pca-login-form.css?ver=

HTML / DOM Fingerprints

CSS Classes
woocommerce-form-rowwoocommerce-form-row--wideform-rowform-row-widewoocommerce-Inputwoocommerce-Input--textinput-text
Data Attributes
data-pca-id
JS Globals
pca_password_form
FAQ

Frequently Asked Questions about PassClip Auth for WordPress