
phpMyDirectory Security & Risk Analysis
wordpress.org/plugins/phpmydirectoryAllows wordpress users to automatically log into phpMyDirectory. The sessions are shared and accounts are created automatically if they do not exist.
Is phpMyDirectory Safe to Use in 2026?
Generally Safe
Score 100/100phpMyDirectory has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of phpmydirectory v1.1 indicates a generally good security posture concerning common attack vectors like AJAX handlers, REST API endpoints, shortcodes, and cron events, as there are zero identified entry points. The code also demonstrates responsible SQL query practices by utilizing prepared statements exclusively, which significantly mitigates SQL injection risks. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security. However, a significant concern arises from the 100% rate of unescaped output, meaning any data displayed to users is susceptible to cross-site scripting (XSS) vulnerabilities. Additionally, while there is one capability check present, the absence of nonce checks on any potential entry points, though the attack surface is currently reported as zero, is a potential weakness if new entry points are introduced in future versions without proper sanitization. The plugin's vulnerability history is clean, with zero recorded CVEs, which suggests a history of stable and secure development, or at least a lack of publicly disclosed vulnerabilities. This, combined with the positive static analysis signals, paints a picture of a plugin that avoids critical vulnerabilities like SQL injection and tainted data flows, but has a notable weakness in output sanitization that could lead to XSS. The lack of a large, unprotected attack surface is a definite strength, but the unescaped output needs immediate attention.
Key Concerns
- 0% of output properly escaped
- No nonce checks found
phpMyDirectory Security Vulnerabilities
phpMyDirectory Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
phpMyDirectory Attack Surface
WordPress Hooks 2
Maintenance & Trust
phpMyDirectory Maintenance & Trust
Maintenance Signals
Community Trust
phpMyDirectory Alternatives
Simple LDAP Login
simple-ldap-login
Integrating WordPress with LDAP shouldn't be difficult. Now it isn't. Simple LDAP Login provides all of the features, none of the hassles.
Sessions
sessions
Powerful sessions manager for WordPress with sessions limiter and full analytics reporting capabilities.
wpDirAuth
wpdirauth
WordPress directory authentication plugin through LDAP and LDAPS (SSL).
Office 365 User Authentication for WordPress
o365-user-authentication
Authenticate and log in WordPress users securely with Office 365 / Azure Active Directory single sign-on.
Active Directory Authentication Integration
active-directory-authentication-integration
Allows WordPress to authenticate, authorize, create and update users through Active Directory
phpMyDirectory Developer Profile
7 plugins · 80 total installs
How We Detect phpMyDirectory
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapdescriptionbutton-primary Copyright 2013 Accomplish Technology, LLC (email: support@phpmydirectory.com) This program is free software; you can redistribute it and/or modify it under the terms of the GNU Lesser General Public License (LGPL) version 3, as published by the Free Software Foundation.+9 morename="phpmydirectory_table_prefix"name="phpmydirectory_folder"name="phpmydirectory_submit_hidden"value="Y"name="Submit"class="button-primary"