
Passwordless Login Security & Risk Analysis
wordpress.org/plugins/passwordless-loginPasswordless login form via a simple to use shortcode: [passwordless-login]
Is Passwordless Login Safe to Use in 2026?
Generally Safe
Score 100/100Passwordless Login has a strong security track record. Known vulnerabilities have been patched promptly.
The "passwordless-login" v1.1.4 plugin exhibits a generally good security posture, with no unprotected entry points identified in the static analysis and all SQL queries utilizing prepared statements. The code demonstrates a focus on security by implementing nonce and capability checks. However, a significant concern arises from the taint analysis, which reveals one flow with an unsanitized path. While the severity of this specific flow is not classified as critical or high, it represents a potential avenue for malicious input to be processed without adequate sanitization, which could lead to unexpected behavior or security vulnerabilities.
The plugin's vulnerability history shows one known CVE, classified as medium severity, related to Cross-Site Scripting. The fact that this vulnerability is no longer present in the analyzed version is positive, but the existence of past XSS issues suggests a potential area of weakness that may require ongoing vigilance. While the plugin demonstrates strengths in its secure handling of database queries and entry points, the presence of an unsanitized path in the taint analysis and a history of XSS vulnerabilities warrant careful consideration. The overall risk is moderate, with the unsanitized path being the primary current concern that needs further investigation.
Key Concerns
- Flow with unsanitized path detected
- Past medium severity XSS vulnerability
Passwordless Login Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Passwordless Login <= 1.1.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Passwordless Login Code Analysis
Output Escaping
Data Flow Analysis
Passwordless Login Attack Surface
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
Passwordless Login Maintenance & Trust
Maintenance Signals
Community Trust
Passwordless Login Alternatives
Login Links – Passwordless Login, Temporary Access Links & Custom Login Form
login-links
Create secure self-expiring login links for temporary access and guest users, and enable passwordless login for registered ones.
Temporary Login Without Password
temporary-login-without-password
Create self-expiring, temporary admin accounts. Easily share direct login links (no need for username/password) with your developers or editors.
Temporary Login
temporary-login
Create a secure, temporary URL for easy access to your WP admin.
User Verification by PickPlugins
user-verification
Email verification for user registration to protect spam.
Magic Login – Passwordless Authentication for WordPress – Login Without Password
magic-login
Passwordless login for WordPress. Streamline the login process by sending magic links to your users.
Passwordless Login Developer Profile
3 plugins · 14K total installs
How We Detect Passwordless Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/passwordless-login/assets/style-back-end.css/wp-content/plugins/passwordless-login/assets/style-front-end.csspasswordless-login/assets/style-back-end.css?ver=passwordless-login/assets/style-front-end.css?ver=HTML / DOM Fingerprints
wpa-wrapwpa-info-wrapwpa-badgewpa-info-textwpa-rowwpa-2-colwpa-calloutwpa-3-col+4 moredata-targetPASSWORDLESS_LOGIN_VERSION[passwordless-login]