PopLogin Security & Risk Analysis

wordpress.org/plugins/poplogin

Stylish Pop-up login for login and register using wp-login core assets.

10 active installs v1.0.0 PHP + WP 4.2+ Updated May 4, 2019
loginlogin-popuppop-uppopupregister
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PopLogin Safe to Use in 2026?

Generally Safe

Score 85/100

PopLogin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The 'poplogin' v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. The high percentage of properly escaped output further contributes to a positive security assessment, indicating that the developers have taken steps to prevent cross-site scripting vulnerabilities.

However, there are notable areas for improvement. The complete lack of nonce checks and capability checks is a significant concern, especially given the presence of a shortcode which can serve as an entry point. While the static analysis reports zero unprotected entry points, the absence of these critical security mechanisms leaves the plugin vulnerable to potential CSRF attacks or unauthorized actions if the shortcode's functionality is not inherently protected through other means. The zero taint flows and zero known CVEs are positive indicators, suggesting no severe or publicly known vulnerabilities at this time. This, combined with the good practices in other areas, suggests a developer who is security-conscious but may have overlooked crucial authentication and authorization checks for their shortcode.

In conclusion, 'poplogin' v1.0.0 is a plugin with a solid foundation in secure coding practices, particularly concerning SQL injection and output escaping. The main weakness lies in the insufficient implementation of security checks for its shortcode. While the vulnerability history is clean, the lack of nonce and capability checks represents a potential avenue for exploitation that could lead to future vulnerabilities. Addressing these specific missing checks should be a priority to further harden the plugin.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Unescaped output (some instances)
Vulnerabilities
None known

PopLogin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

PopLogin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
24 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped29 total outputs
Attack Surface

PopLogin Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[poplogin_form] public\poplogin-tswplugin-public.php:126
WordPress Hooks 6
actionadmin_menuadmin\poplogin-tswplugin-admin.php:12
actionadmin_initadmin\poplogin-tswplugin-admin.php:13
actionplugins_loadedincludes\poplogin-tswplugin.php:24
actionwp_enqueue_scriptsincludes\poplogin-tswplugin.php:52
actionwp_footerpublic\poplogin-tswplugin-public.php:37
filterwp_nav_menu_itemspublic\poplogin-tswplugin-public.php:38
Maintenance & Trust

PopLogin Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedMay 4, 2019
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

PopLogin Developer Profile

tradesouthwest

17 plugins · 2K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PopLogin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about PopLogin